Back to skill

Security audit

股票交易下单买卖和查询。

Security checks across malware telemetry and agentic risk

Overview

This skill is openly for stock trading, but it gives an agent high-impact trading and account access through a local API with a documented default key and weak safety guidance.

Review before installing. Use only with a verified trading assistant, change the default API key before use, prefer paper trading first, and require manual confirmation for every buy, sell, or cancellation request.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Context-Inappropriate Capability

High
Confidence
99% confidence
Finding
The documentation exposes a usable default API key for authenticated trading and account operations. Even though the endpoint is localhost, publishing a shared default credential materially lowers the barrier to unauthorized order placement, cancellation, and account/position access wherever the local trading bridge is installed with default settings.

Missing User Warnings

High
Confidence
95% confidence
Finding
This skill enables real-money trading, order cancellation, and access to sensitive financial account data but does not warn about financial loss, irreversible actions, or the need for explicit confirmation before execution. In this context, omission of safety guidance is dangerous because an agent may automate high-impact brokerage actions without adequate user awareness or consent safeguards.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:40