Back to skill

Security audit

SK Hynix 2x Open Estimator

Security checks across malware telemetry and agentic risk

Overview

This skill is a transparent calculator for estimating HK 07709 values and does not fetch data, store credentials, trade, or persist background behavior.

Before installing, confirm you are comfortable with the agent collecting current market quotes and product filings for this valuation task. The calculator does not trade or fetch data itself, but the result is only an estimate and should not be treated as a guaranteed executable price or financial advice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Low
Confidence
93% confidence
Finding
The markdown requires outputs labeled as `NAV理论价`, `折价延续价`, and `ADR信号价`, and the formulas continue using Chinese-only field names. This imposes a specific language/locale in the skill's user-facing output without documenting user choice or opt-in, which matches the language-policy violation category.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
This code emits multiple user-visible strings in Chinese, beginning with the carried-price label at L121 and continuing throughout the CLI output. Because the file does not indicate that the skill is region-specific or provide an opt-in language choice, it violates the language/locale policy for natural-language content.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.