Back to skill

Security audit

0-sentisense-onboarding

Security checks across malware telemetry and agentic risk

Overview

This is a read-only onboarding guide for SentiSense stock-market skills, with a disclosed API key requirement and no hidden execution or persistence.

Before installing, be comfortable sharing a SentiSense API key with the environment where the agent runs. Use the most specific stock-market skill for the task when possible, and treat outputs as research rather than financial advice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The fallback guidance is broad enough to route many loosely related requests to the general `sentisense` skill, which increases the chance an agent will select a more permissive or less task-specific capability than necessary. In a skill-routing system, ambiguous catch-all triggers can cause over-collection of data, incorrect workflow selection, or unintended use of a general API surface when a narrower skill would have reduced risk and scope.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.