Back to skill

Security audit

A股实战决策专家

Security checks across malware telemetry and agentic risk

Overview

This is a coherent A-share trading-analysis skill, but it gives highly actionable speculative trading guidance with broad triggers and weak financial-risk disclosure, so users should review it carefully before installing.

Install only if you intentionally want an aggressive A-share trading assistant. Before using it, narrow the trigger phrases, add clear educational-only and capital-loss warnings, require explicit confirmation before any Buy/Sell or sizing recommendation, and keep monitoring, notifications, and decision-history storage opt-in with clear retention and deletion rules.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The document establishes a strict hard-stop loss rule ('无论任何理由' / regardless of any reason) but later recommends continuing to hold a position after that stop has already been breached. In a trading-discipline skill, this contradiction can cause users or downstream automation to ignore loss controls, increasing financial harm and undermining the safety guarantees the framework claims to provide.

Intent-Code Divergence

Medium
Confidence
88% confidence
Finding
The text says notifications are only user-triggered or user-decided, but the provided code path automatically sends alerts when rules fire. This mismatch can lead to unauthorized or unexpected outbound messaging behavior, especially if integrated into scheduled jobs, and creates a reliability/safety issue because user consent semantics are inaccurately represented.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger list is extremely broad and includes very common finance-related words such as '股票', '价格', '持仓', and '行情', which can cause the skill to activate for many ordinary conversations beyond its intended scope. In an agent environment, overbroad activation increases the chance that high-risk trading instructions, tool-routing rules, and external data workflows are invoked when the user did not explicitly request this specialized behavior.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly recommends maintaining persistent decision history and automatically injecting past analyses into future prompts, but it does not mention user consent, retention limits, deletion controls, or any warning that analysis history may be stored. In a financial-analysis context, those records can reveal user interests, holdings, strategy preferences, and behavior over time, creating avoidable privacy and profiling risk if stored by default or reused broadly.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger list for the post-market review scenario includes extremely generic phrases like '今天' and '收盘', which can match ordinary conversation and cause unintended invocation of the skill workflow. In a financial-analysis skill, accidental triggering is risky because it may produce unsolicited market analysis or portfolio-related guidance in contexts where the user did not explicitly request it.

Vague Triggers

Medium
Confidence
90% confidence
Finding
Several scenario triggers are broad terms such as '推荐', '机会', '最新', and '基本面', which are ambiguous and can overlap with normal user phrasing outside the intended workflow. Because the skill is designed for stock screening and trading-related analysis, loose trigger matching can lead to unintended execution of financial recommendation flows, increasing the chance of inappropriate or unauthorized advice generation.

Missing User Warnings

High
Confidence
98% confidence
Finding
The file is an actionable trading playbook that instructs users how to identify, enter, size, and manage speculative A-share momentum trades, but it provides no meaningful warning about financial risk, suitability, capital loss, volatility, or the non-advisory nature of the content. The context makes this more dangerous because it explicitly encourages chasing highly speculative 'theme炒作' setups, normalizes buying loss-making stocks, and gives operational screening steps and buy/sell heuristics that a user could directly follow as investment advice.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.