Back to skill

Security audit

Trade Decision Policy

Security checks for vulnerabilities and agentic risk

Overview

This finance-platform skill is broad and uses authenticated cloud services, but its access and workflows are disclosed and aligned with its stated purpose.

Install this only if you want an agent to use Alva for financial data, cloud analytics, dashboards, backtests, and scheduled playbooks. Expect npm CLI installation, Alva login, use of Alva cloud storage, and possible persistent automations; review any plan before approving builds or releases, and do not use it as financial advice without independent verification.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill description is overly broad and can cause the agent to activate in loosely related finance contexts without clear boundaries. In a trading workflow, this increases the risk of the skill being invoked on incomplete, low-confidence, or mis-scoped inputs, potentially producing recommendation labels or action drafts that users may over-trust.

Static analysis

No suspicious patterns detected.