Back to skill

Security audit

Options Trading Brain

Security checks across malware telemetry and agentic risk

Overview

This options-analysis skill fetches public market data for tickers and does not show credential access, persistence, or destructive behavior.

Install only if you are comfortable with ticker lookups being sent to yfinance/Yahoo Finance data sources. Treat the output as informational trading analysis, not verified financial advice, and review any generated trade idea before acting on it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
80% confidence
Finding
The skill description does not disclose that embedded scripts make live external network requests via yfinance, which can surprise users and operators, leak requested tickers or usage patterns to third parties, and violate least-surprise/privacy expectations. In an agent environment, hidden outbound network behavior is more dangerous because invocation may happen automatically on broad prompts.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.