Back to skill

Security audit

Backtest Free

Security checks across malware telemetry and agentic risk

Overview

This backtesting skill is not overtly malicious, but it asks for broad command execution while giving vague security assurances and includes investment-style recommendations with limited warnings.

Review before installing. Use this only with data and commands you intentionally provide, avoid running it with elevated privileges, independently verify any package it installs, and treat all predictions or trading signals as informational analysis rather than financial advice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The skill claims that risky code was removed and security was enhanced, yet the manifest still declares the `exec` tool. This creates a misleading trust signal that may cause downstream agents or users to treat the skill as safer than it is, while it still retains broad command-execution capability that could be used for arbitrary local actions if invoked.

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The document states that only whitelisted commands are executed, but the skill file provides no evidence of such enforcement and still exposes the broad `exec` capability. In security-sensitive agent ecosystems, unsupported claims about command restrictions are dangerous because reviewers or orchestrators may assume protections exist when they do not.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The activation text says to use the skill whenever the user needs strategy backtesting-related functionality, which is broad in a finance context and may trigger the skill for loosely related requests. Because the skill also declares `exec`, overbroad routing increases the chance that powerful capabilities are invoked in contexts where they are unnecessary or insufficiently scrutinized.

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The skill includes trading signals, trend predictions, and investment-style recommendations without a clear, prominent warning that outputs are informational and must not be used as sole financial advice. In a finance skill, this context makes the issue more serious because users may rely on automated recommendations for real-world investment decisions, creating financial and compliance risk.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.