Back to skill

Security audit

黄金白银行情日报

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent gold/silver daily report generator that uses disclosed web research, local scripts, and a local HTML output without hidden upload, credential use, or destructive behavior.

Install this if you want an agent-assisted gold and silver market report workflow. Expect it to browse public market-data sources and create a local HTML file; the rendered report may contact jsDelivr for ECharts unless you modify it for offline use. Treat generated market commentary as research material, not investment advice, and review source data before sharing or relying on the report.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger phrases are broad natural-language requests such as '生成今天的黄金白银行情日报' and '做一份黄金白银 HTML 研报' without explicit negative boundaries or disambiguation rules. In an agent ecosystem with automatic skill selection, this can cause the skill to activate on loosely related finance queries, increasing the chance of unintended network access, report generation, or incorrect workflow takeover.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.