Back to skill

Security audit

Elliott Wave Counts

Security checks across malware telemetry and agentic risk

Overview

This is a small market-signal skill that sends a ticker to a remote API, which fits its purpose, but its disclosure of the external service and payment flow is incomplete.

Before installing, understand that ticker queries are sent to an external API and premium responses may require payment. Treat the returned market predictions as third-party financial information, not verified investment advice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill description and usage imply that it connects to an external service for market signals, yet there is no clear warning or disclosure about outbound connectivity, data sharing, or the premium payment requirement. In a financial/prediction context, hidden external dependencies are more dangerous because users may rely on opaque third-party outputs or expose sensitive trading interests without informed consent.

Missing User Warnings

Low
Confidence
88% confidence
Finding
The skill sends the user-supplied ticker to an external third-party endpoint without any disclosure, consent, or indication that user input leaves the local skill boundary. Even though a ticker symbol is typically low-sensitivity data, this still creates an avoidable privacy and transparency issue and exposes user queries to the remote service operator.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.