Back to skill

Security audit

Money Claw · US Stocks

Security checks across malware telemetry and agentic risk

Overview

The skill is a disclosed stock-screening and risk-check workflow with local scoring scripts; it does not collect credentials, persist in the background, or place trades.

Treat this as high-risk trading research software, not as financial advice. Before using any EXECUTE or entry label, independently verify live quotes, SEC filings, dilution risk, halts, spread, and your own suitability; do not connect it to broker execution without a separate security and compliance review.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The file defines trading signals and execution-style outputs such as EXECUTE, WAIT_OPEN, and EXCLUDE for highly volatile low-float squeeze scenarios, but it does not include an explicit risk warning or decision-support disclaimer near the operational guidance. In this context, users could over-trust the model as a direct trading decision engine for extreme speculative events, increasing the chance of financial harm from misuse.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
tests/test_classify_intraday_phase.py:18