Back to skill

Security audit

热门赛道与ETF深度投研

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Cue-powered ETF research helper that sends user queries to Cue services and uses a local Cue API key, with no hidden files or executable payloads in the artifact.

Install only if you are comfortable sending ETF names, sector research questions, and your Cue API-authenticated requests to Cue-operated services. Keep your Cue API key private, run the diagnostic commands only in trusted shells, and review generated investment research as informational rather than trading advice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly states that user queries and the Cue API key are sent to external Cue services and downstream data sources, but it does not present a clear, upfront privacy/data-sharing warning before use. This can cause users to disclose sensitive financial intent, portfolio details, or identifiers to third parties without informed consent.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The health-check command reads the user's API key from a local config file or environment and sends it in Authorization headers to remote endpoints, yet the skill provides no safety warning about credential handling. This increases the risk of inadvertent token exposure, especially if users run diagnostics in shared shells, logs, or monitored environments.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.