Back to skill

Security audit

Stock Expert

Security checks across malware telemetry and agentic risk

Overview

This skill is for stock trading and says so, but it can use brokerage credentials and place real orders through an unbundled local script with weakly scoped command inputs.

Install only if you trust the publisher and have reviewed the exact kis_trade.py file you will point KIS_TRADE_SCRIPT_PATH to. Use test or least-privilege brokerage credentials if possible, keep the script path controlled, and require explicit confirmation of account, symbol, side, quantity, and price before every order.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal