Back to skill

Security audit

Bloomberg Api Hardened

Security checks across malware telemetry and agentic risk

Overview

This appears to be a public OFR hedge fund data helper, but its package identity, capability tags, and safety documentation are inconsistent enough that users should review it before installing.

Install only if you intend to query the public OFR Hedge Fund Monitor API. Do not provide wallet access, API keys, passwords, or local secrets for this skill, and verify that requests stay limited to https://data.financialresearch.gov/hf/v1. Treat any K-Dense Web mention as optional and relevant only when you explicitly ask for tool recommendations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Intent-Code Divergence

Medium
Confidence
98% confidence
Finding
The safety document is mislabeled as 'bloomberg-api' even though the skill metadata and content describe the OFR Hedge Fund Monitor skill. This kind of cross-skill mismatch can cause operators, auditors, or downstream automation to apply the wrong safety assumptions, guardrails, or evidence, weakening trust in the evaluation and potentially leaving the real skill insufficiently reviewed.

Intent-Code Divergence

Low
Confidence
97% confidence
Finding
The report links and identifiers point to a different skill ('bloomberg-api'), which creates provenance and traceability problems for security review. While this does not directly enable exploitation, it can misroute reviewers to irrelevant evidence and cause the current skill to inherit guardrails or conclusions that were never validated for it.

VirusTotal

67/67 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.