Back to skill

Security audit

Multi Research

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a financial research assistant, but it requests broad command execution and gives investment recommendations without adequate guardrails or disclaimers.

Review this before installing. It may be useful for A-share research, but only use it if you are comfortable granting command execution in your agent environment and configuring market-data API keys. Treat all outputs as informational research, not personalized financial advice, and independently verify any trade decision.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Intent-Code Divergence

Medium
Confidence
89% confidence
Finding
The document claims that risky code and external dependencies were removed, yet the skill still advertises the exec tool and explicitly documents command-execution failure handling. This inconsistency is security-relevant because it can mislead reviewers and users into trusting a skill that still retains a dangerous capability, increasing the chance that arbitrary command execution is overlooked.

Context-Inappropriate Capability

High
Confidence
95% confidence
Finding
A generic command-execution capability is not justified by an A-share investment research skill whose described functions are analysis, scoring, and reporting. Unnecessary exec access materially expands the attack surface: if the skill is invoked with adversarial input or chained with other tools, it could run arbitrary system commands, access local data, or facilitate lateral abuse.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The activation text is broad enough to trigger on generic requests related to analysis, which can cause the skill to activate outside its intended financial-research scope. Over-broad matching is dangerous because it increases unintended exposure of the skill’s capabilities, especially when the skill also declares exec access.

Missing User Warnings

High
Confidence
91% confidence
Finding
The skill presents investment advice and recommendations without a clear warning that outputs are not financial advice and may be incomplete or wrong. In a financial context, users may rely on these outputs for real-money decisions, creating significant harm from misleading or overconfident recommendations.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.