Back to skill

Security audit

Sim Trade

Security checks across malware telemetry and agentic risk

Overview

The local simulator code is mostly straightforward, but the skill asks users to store full browser cookies or broker API tokens for external account access without clear scoping or a real implemented integration.

Using the local simulation and quote lookup appears reasonable. Treat the external-platform setup as high risk: do not paste full Cookies or broker tokens unless the provider clearly documents the exact access needed, where the credentials go, and how to revoke or delete them.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.