Back to skill

Security audit

Composer Optimizer

Security checks across malware telemetry and agentic risk

Overview

This skill locally analyzes Composer strategy data and writes an allocation report without trading, deleting data, or sending information elsewhere.

Before installing, note that this is financial allocation code using local cached account strategy data and rough synthetic assumptions; review the generated recommendations yourself and be aware that the actual output path is dashboard/composer_trad_ira_optimized.json.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Intent-Code Divergence

Low
Confidence
97% confidence
Finding
The header says the skill outputs `trading_bot/composer_optimized_trad_ira.json`, but the code sets `OUTPUT` to `dashboard/composer_trad_ira_optimized.json` and later writes to that path. This is an active documentation-vs-code contradiction about where the artifact is produced.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.