Back to skill

Security audit

vibe-trading

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed finance research and backtesting toolkit with optional broker and API integrations, so the main user risk is careful handling of financial credentials and account data.

Before installing, treat this as a powerful finance workstation integration: only enable broker connectors and external MCP servers you trust, keep API keys out of chats and version control, prefer read-only or paper profiles first, and do not enable direct write/trading tools unless you intend the agent to have that authority.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill shows a config example with hard-coded placeholders for `x-api-key` and `x-user-key` in an MCP server definition but does not place an adjacent warning telling users not to paste secrets into shared files, prompts, logs, or version control. In an agent-oriented workflow, users often copy examples verbatim, which increases the chance that real credentials will be stored insecurely or exposed through chat history, screenshots, or repository commits.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.