Massive(polygon.io) Stock Data Feed

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate market-data skill, but its setup script installs a questionable Python package name while the skill asks for sensitive API and S3 credentials.

Install only after reviewing or replacing the setup dependency with the official Massive Python client package. Provide the API key only if you intend to use this data source, provide S3 keys only for Flat Files, keep all credentials in a secret manager or uncommitted .env file, and monitor API usage and billing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
83% confidence
Finding
The trigger text is extremely broad and may cause the skill to activate on many generic requests related to prices, market data, history, streaming, or backtesting across multiple asset classes. Over-broad routing increases the chance of unnecessary external calls and unintended credential use in contexts where this skill was not specifically requested.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal