Security audit
stock-earnings-analysis
Security checks across malware telemetry and agentic risk
Overview
This skill is a read-only earnings-analysis helper that uses a disclosed SentiSense API key and does not request trading, wallet, write, persistence, or local-data access.
Installers should understand that this skill depends on a third-party SentiSense API key and sends requests to SentiSense for read-only financial research data. It is not designed to trade or change accounts, but outputs should still be treated as research and not investment advice.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
