Back to skill

Security audit

Trading Research Team — Agent Configuration Bundle

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly transparent, but it combines autonomous trading authority with shell execution and external tool invocation without clear approval limits or safety boundaries.

Review this skill carefully before installing. It should only be used with least-privilege trading credentials, explicit human approval for orders or fund-affecting actions, command restrictions for shell execution, and clear audit and kill-switch controls. There is no evidence of malicious behavior, but the current artifact under-documents high-impact trading authority.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly grants an `autonomous-trader` role both trading authority and dangerous local execution capabilities (`shell_exec`, plus `mcp.invoke`) without any prominent warning, approval boundary, or restriction language. In a trading context, this combination can lead to unauthorized orders, operational misuse of external integrations, or host-level actions, making the omission materially risky rather than merely informational.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.