Security audit
stock-screener
Security checks across malware telemetry and agentic risk
Overview
This is a coherent read-only stock and ETF screening skill that uses a SentiSense API key to query financial data, with no evidence of trading, destructive actions, or hidden behavior.
Before installing, be comfortable providing a SentiSense API key and making requests to SentiSense. Treat results as research data, not investment advice, and use the optional CLI credential storage only if you are comfortable keeping the key on this machine.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
