实时财经数据

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward finance quote skill that sends market lookup requests to Sina Finance and Yahoo Finance, with no evidence of hidden access, persistence, credentials use, or destructive behavior.

Install only if you are comfortable with finance-related queries being sent to Sina Finance and Yahoo Finance. Consider narrowing the trigger phrases if accidental activation would be a problem, and prefer HTTPS for the Sina request if the provider supports it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
Several triggers are broad, common finance-related words such as “实时”, “指数”, “黄金”, and “原油”, which can appear in ordinary conversation and cause the skill to activate unintentionally. Unintended invocation is risky here because activation leads to code execution and external network requests, potentially leaking user queries to third-party data sources without clear intent.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal