Quant Strategy Development

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only Chinese quant-strategy development guide with disclosed live-trading examples, not hidden code or data access.

Safe to install as a documentation-style skill. Treat generated trading code as financially sensitive: review it manually, backtest it, use hard account and position limits, avoid hard-coding credentials, and require explicit human approval before connecting it to a live brokerage or QMT account.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The skill metadata and description are written to auto-trigger on Chinese phrases and are explicitly Chinese-language only, without indicating that the assistant should adapt to the user's preferred language. This can override user expectations, reduce usability, and in some deployments create prompt-steering behavior that constrains responses in ways the user did not request.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal