Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md node scripts/prepare_data.mjs NVDA > /tmp/nvda.json
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed, read-only market-data visualizer that fetches SentiSense data and creates a local HTML chart without hidden persistence or account actions.
Install only if you are comfortable giving this skill a SentiSense API key and allowing read-only requests to app.sentisense.ai at build time. Review generated charts as educational market-data snapshots, not trading advice; the skill does not place trades or modify accounts.
Referenced artifact was not completely inspected
node scripts/prepare_data.mjs NVDA > /tmp/nvda.json
Without declared permissions the skill's intent is opaque and cannot be validated.
Subtle instructions detected that may alter agent decision-making or introduce hidden biases.
- When implied sits above realized, the honest phrasing is that options are pricing more movement than the stock has recently delivered. That is an observation about pricing, not a trade.
- Never turn the band edges into targets, and never attach a probability more precise than the model supports.
- On a preview response, say the 60 and 90 day bands are missing because the free monthly dossier allowance is spent, rather than presenting a one-band chart as the whole picture.
- When the next report is unknown because the free calendar covers one week, say exactly that. Never tell the user nothing is scheduled, and say a report inside the window cannot be ruled out.
## Going further
The money() formatter uses toLocaleString("en-US", ...), which forces U.S. locale output regardless of user preference. This is a natural-language/locale policy concern because the file imposes a specific locale without any opt-in or documented justification.
Detected: suspicious.env_credential_access