Back to skill

Security audit

News Sentiment Tool Free

Security checks across malware telemetry and agentic risk

Overview

This is a stock sentiment-analysis skill with expected command and network use, but its trigger wording is broader than the stated purpose and the referenced script is not included.

Before installing, understand that this skill is intended for stock sentiment monitoring and may run local Python commands and fetch public financial or social-media data. Treat its outputs as investment research support only, not financial advice, and be aware that the packaged artifact does not include the referenced sentiment_scan.py script.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger condition is overly broad ('use when data analysis, report generation, statistical insights, visualization are needed'), which can cause the agent to invoke this skill for many unrelated requests. Because the skill has exec and network-capable behavior elsewhere in the file, accidental activation could lead to unnecessary command execution and external data access beyond user expectations.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill describes multi-source collection from news, announcements, and social media, and the metadata allows exec, but the user-facing overview does not clearly warn that using the skill may perform command execution and external network retrieval. This creates a transparency and consent issue: the agent may fetch outside data and run local scripts when the user believes they are only getting passive analysis.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.