Back to skill

Security audit

多视角投研分析

Security checks across malware telemetry and agentic risk

Overview

This skill is a finance-analysis prompt package that asks for broad agent tools and API-key use while making unsupported claims about security controls and investment-analysis capability.

Review carefully before installing. Only use it for informational research, not as a trading authority; verify market data independently, avoid storing API keys through this skill unless the host platform provides secure secret management, and require explicit confirmation before running commands, installing packages, writing files, or producing buy/sell recommendations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The skill asserts that security controls such as encrypted key storage, TLS/SSL, AES encryption, input validation, logging redaction, key rotation, and vulnerability scanning are already implemented, but this Markdown file contains no executable implementation or enforceable configuration for any of them. These unsupported assurances can cause users or downstream agents to trust the skill with sensitive API keys or data under false security assumptions, increasing the chance of credential exposure or unsafe operation.

Intent-Code Divergence

Medium
Confidence
89% confidence
Finding
The document describes advanced machine-learning behavior, data fusion, and predictive analysis as if they are provided by the skill, but the file is only descriptive Markdown and does not implement or verify those capabilities. This can mislead users into relying on unsupported financial analysis outputs, especially in an investment context where inaccurate or fabricated capability claims can drive risky decisions.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The activation description is broad and vague ('use when users need multi-view research analysis related functionality'), which can cause an agent to invoke the skill in situations beyond its real scope. In a finance setting, overbroad activation increases the risk of the agent presenting speculative or incomplete investment analysis as appropriate advice, especially when the skill also advertises many unsupported capabilities.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill promotes stock analysis and investment suggestions but does not include a clear warning that outputs may be inaccurate, incomplete, non-fiduciary, and unsuitable as sole grounds for trading decisions. Because the domain is financial decision-making, omission of an investment-risk warning makes the context more dangerous by increasing the likelihood that users or agents over-trust generated advice and incur financial harm.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.