Back to skill

Security audit

hectorlee-volume-price-screener

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed A-share stock-screening skill that uses market data, local files, and a local TDX MCP connector for its stated purpose, with some privacy and accuracy cautions but no evidence of deception or harmful actions.

Install only if you want this agent to perform A-share technical screening and diagnostics. Expect it to call public market-data endpoints, use a local TDX MCP connector if available, read any holdings file you explicitly provide, and write local cache/history/export files. Treat its outputs as analysis rather than investment advice, and only load pickle model/cache files from this trusted package or files you created yourself.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Lp3

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding
The skill advertises and instructs use of capabilities including network access, MCP connectivity, and local file read/write, but does not declare permissions or present clear boundaries for those operations. That mismatch weakens user consent and platform enforcement, increasing the risk of unexpected data access, external communication, or local persistence when the skill is invoked.

Description-Behavior Mismatch

Medium
Confidence
97% confidence
Finding
The skill metadata advertises a 135-point scoring system, but this file defines a 100-point model. In an automated trading or stock-screening workflow, this inconsistency can cause downstream components, operators, or users to misinterpret scores, thresholds, and ranking behavior, leading to incorrect security/quality assumptions about the agent’s output. The domain context increases risk because financial decision support depends on deterministic, well-documented scoring semantics.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are broad financial terms such as '量价选股', '突破延续', and '盘中监控' that can plausibly appear in ordinary market discussion. Overbroad activation can cause the skill to run in contexts the user did not intend, which is more concerning here because the skill can perform network and file operations and produce trading-related outputs.

Missing User Warnings

Low
Confidence
87% confidence
Finding
The skill explicitly supports '持仓诊断' using a user-provided holdings file, but the documentation does not clearly warn that local file contents will be read and processed. This creates a consent and privacy issue: users may provide or reference files without understanding that portfolio contents and possibly adjacent metadata will be ingested, analyzed, and potentially written into output logs or signal files.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger list contains broad, common finance phrases such as 量价选股, 突破延续, and 盘中监控 that could match many ordinary stock-analysis requests, causing the skill to activate outside the user's intended scope. In a finance context, overbroad activation is risky because it can steer conversations toward a specific trading system or data dependency without clear user opt-in, leading to inappropriate tool use or biased investment guidance.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.