Back to skill

Security audit

Options Trading Backtester

Security checks across malware telemetry and agentic risk

Overview

This skill does not look like malware, but it overstates its financial backtesting capabilities in ways users could rely on for trading decisions.

Review carefully before installing or using this for trading. Treat its outputs as synthetic demonstration data, not a realistic options backtest, unless the missing strategy logic, historical data loading, and documented risk checks are implemented and independently verified.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The manifest claims support for multiple options strategies and historical or real-data backtesting, but the included code only runs a simplified Iron Condor simulation using randomly generated prices. This mismatch can mislead users into making financial decisions based on fabricated or incomplete analysis, especially in a finance skill where users may trust the advertised capabilities.

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The usage examples and error-handling section describe strategy modes and safety checks that are not implemented in the code, such as alternate strategy logic, IV/spread rejection, and expiration filters. In a trading context, these false assurances can cause users to rely on risk controls that do not exist, increasing the chance of unsafe financial decisions or incorrect automation outputs.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.