Back to skill

Security audit

Ashare Fund Intel

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only finance reporting skill that uses public market sources and an included portfolio file to generate A-share and fund reports, with no code execution, credentials, or hidden data movement found.

Before installing, review or replace the included portfolio-current.md so reports do not use someone else's holdings. Use the generated allocation ranges as informational analysis only, and verify important claims against the cited sources before making financial decisions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger section uses broad descriptions such as "A-share/China market daily monitoring" and "bullish/bearish signal summary for position adjustment" without defining exact invocation scope, exclusions, or negative examples. This makes it unclear when the skill should activate versus when a general market discussion should not invoke it.

Natural-Language Policy Violations

Low
Confidence
92% confidence
Finding
This markdown template contains substantial Chinese-language instructions and headings while also embedding English section names such as 'Bullish factors' and 'Position suggestion'. Because the file does not state that it is region-specific or offer any language/locale choice, it may violate a language/locale policy that requires user opt-in or explicit justification.

External Transmission

Medium
Category
Data Exfiltration
Content
- 上证指数: https://quote.eastmoney.com/zs/000001.html
- 沪深300: https://quote.eastmoney.com/zs/000300.html
- 创业板指: https://quote.eastmoney.com/zs/399006.html
- 北向资金: https://data.eastmoney.com/hsgtcg/
- 两融数据: https://data.eastmoney.com/rzrq/

## C. 基金与净值观察
Confidence
50% confidence
Finding
https://data.eastmoney.com/

External Transmission

Medium
Category
Data Exfiltration
Content
- 沪深300: https://quote.eastmoney.com/zs/000300.html
- 创业板指: https://quote.eastmoney.com/zs/399006.html
- 北向资金: https://data.eastmoney.com/hsgtcg/
- 两融数据: https://data.eastmoney.com/rzrq/

## C. 基金与净值观察
Confidence
50% confidence
Finding
https://data.eastmoney.com/

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.