Financial Financial Analysis

Security checks across malware telemetry and agentic risk

Overview

This is a Markdown-only financial research workflow skill with no hidden execution, installer scripts, credential handling, or persistence found.

Install only if you want an agent to help draft equity research and investment-analysis materials. Verify market data and source licensing yourself, and do not treat generated reports or trade ideas as professional financial advice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The skill instructs the agent to generate and package new skill files, which implies filesystem writes and creation of executable workflow artifacts, but it does so without explicit safety boundaries, destination constraints, or user confirmation before modification. In an agentic environment, this can lead to unintended file creation or overwriting, especially if a user-supplied path or template is malicious or ambiguous.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal