Back to skill

Security audit

Agent Research

Security checks across malware telemetry and agentic risk

Overview

This skill is an A-share investment-research guide, but it asks for command execution and financial API credentials while mixing unrelated SEO triggers and making unsupported safety claims.

Install only after confirming you want an agent with command execution and financial-data/API-key access for A-share research. Treat outputs as informational, require human review before any investment or trading action, and avoid using it in environments with sensitive credentials unless commands, endpoints, and data sources are constrained.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Intent-Code Divergence

High
Confidence
97% confidence
Finding
The documentation claims risky code and external dependencies were removed, yet the same file describes API-key configuration, external data-source access, and command execution. This contradiction can mislead users and reviewers into granting the skill more trust and permissions than warranted, increasing the chance of unsafe execution in a high-impact financial context.

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The skill states that untrusted external calls are restricted, but elsewhere it advertises broad external API/data access and runtime execution behavior. Inconsistent security claims weaken operator judgment and can cause deployment into environments where outbound access or execution should have been scrutinized more closely.

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The manifest description mixes SEO optimization use cases with A-share investment research, creating a materially misleading statement of purpose. Purpose confusion is dangerous because it can trigger the skill in inappropriate workflows, bypass expected review, and obscure the real financial-analysis and possible execution behavior.

Context-Inappropriate Capability

Medium
Confidence
89% confidence
Finding
The skill requests exec capability even though the visible documentation does not clearly justify why shell or command execution is necessary for investment research. Unnecessary execution permissions expand the attack surface and, combined with API-key handling and external data access, could enable unsafe local actions or abuse of host resources.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The invocation guidance is broad and ambiguous, including unrelated SEO-oriented language and generic use conditions. Overbroad triggers raise the chance the skill is auto-selected in contexts it was not designed for, which is especially risky when the skill also touches financial decision support and elevated capabilities.

Missing User Warnings

High
Confidence
96% confidence
Finding
The documentation promotes investment decision support, strategy optimization, and integration with trading workflows without a prominent warning that outputs can materially affect financial decisions. In a finance context, missing risk disclosures and human-review requirements can lead users to over-trust automated recommendations and potentially execute harmful trades.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.