Back to skill

Security audit

A Stock Monitor

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only A-share stock analysis skill with disclosed market-data and cron guidance, but users should treat its trading recommendations as informational only.

Install only if you understand this is not professional financial advice. Verify any market data and trading signals independently, review the optional cron task before enabling it, and be aware that the published artifact does not include the referenced scripts or web UI files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill prominently advertises automated stock selection, buy/sell point calculation, stop-loss/take-profit guidance, and daily recommendations, but provides no visible financial-risk disclaimer or statement that outputs are informational rather than investment advice. In a trading context, users may over-trust the system’s recommendations and act on them without understanding model limits, data quality issues, latency, or market risk, increasing the chance of financial harm.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal