Back to skill

Security audit

trading-book-library

Security checks across malware telemetry and agentic risk

Overview

This skill is a trading-education reference with no executable code or requested permissions, though its local lookup path is brittle and should be treated cautiously.

Install only if you are comfortable with the agent reading the named local corpus path for chapter lookup. Treat the trading material as educational, verify any financial claims independently, and confirm the publisher has rights to distribute the extracted book content.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Context-Inappropriate Capability

Medium
Confidence
85% confidence
Finding
The manifest describes a consolidated trading knowledge resource for analysis and framework application, which implies providing trading content rather than operational guidance for navigating a host filesystem. Lines L100-L104 direct the agent to access a concrete local path under a user temp directory and use file-search/read tooling, a capability not justified by the high-level purpose of a trading reference library.

Context-Inappropriate Capability

Low
Confidence
82% confidence
Finding
The manifest frames this skill as a knowledge resource for trading analysis, but the documentation exposes an implementation-specific local temp directory and instructs the agent to perform direct filesystem lookup and streaming from that path. Accessing a host-local path is not an obvious capability implied by a trading literature reference skill, even if used to retrieve the corpus.

Missing User Warnings

Low
Confidence
83% confidence
Finding
This markdown file instructs the agent to access a local temp-directory file containing a large extracted corpus. For markdown files, SQP-2 applies when the skill description omits warnings about behaviors that could affect user data, privacy, or system integrity; here, the instructions describe local file access but provide no disclosure or caution to the user.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.