Back to skill

Security audit

macd-stock-screener

Security checks across malware telemetry and agentic risk

Overview

This skill runs a disclosed A-share MACD stock screener, fetches public market and sentiment data, and writes local reports without hidden credential access, persistence, or trading authority.

Install only if you want a Chinese-language A-share MACD screener that may make many public data requests and write reports under an outputs directory. Treat results as screening information, not investment advice; the skill does not place trades or access brokerage accounts.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Lp3

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding
Without declared permissions the skill's intent is opaque and cannot be validated.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger list includes generic phrases like “选股” and broad conditions like “用户需要每日例行 MACD 选股” and “自动化任务触发选股流程,” which do not clearly distinguish when this skill should activate versus other stock-related tasks. The file also lacks negative examples or tighter scope boundaries for invocation.

Natural-Language Policy Violations

Medium
Confidence
83% confidence
Finding
All natural-language instructions, triggers, and outputs are specified only in Chinese, with no indication that the user may choose another language. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern unless the locale restriction is explicitly justified.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.