Questrade

Security checks across malware telemetry and agentic risk

Overview

This Questrade skill supports manual trade preparation and quote checks, and its code does not show hidden broker control, secret collection, or persistence.

Use this only when you intend to prepare or review Questrade trades. Keep actual order submission manual, verify symbol/side/quantity/prices yourself, keep generated files local or redacted, and never provide passwords, MFA codes, cookies, API keys, or session tokens to the agent.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding
The skill directs use of local scripts, file generation, and live quote retrieval, which implies file read/write and network capabilities, but it does not declare permissions explicitly. In a trading workflow, undeclared capabilities reduce transparency and can bypass expected operator review, increasing the risk of unintended data access, local artifact leakage, or outbound requests during sensitive financial operations.

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal