Back to skill

Security audit

Market Sentiment

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed market-sentiment analysis tool that reads user-provided CSV data and produces financial context, without hidden access, persistence, or trade execution.

Install only if you want CSV-based market sentiment summaries for financial research. Treat the output as advisory context, verify that the stock-planner market parameter meanings match your workflow, and do not rely on it as the sole basis for trading decisions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The README shows a contradictory mapping where a strong/overbought market example outputs `stock-planner: --market bear`. If users copy this integration pattern, downstream trading logic may receive the opposite market regime and produce materially incorrect portfolio actions. In a financial decision-support skill, misleading parameter mappings are safety-relevant because they can systematically invert recommendations.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger list contains broad terms such as 'sentiment', 'summary', 'market context', and generic market-state phrases that could cause the skill to activate in conversations where the user did not intend to invoke this specific tool. Over-broad invocation increases the chance of context hijacking, wrong-tool execution, or unintended propagation of this skill's outputs into downstream trading workflows.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.