quotedance-market

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a disclosed market-report generator that fetches market/news data and writes local cache files, with no artifact-backed evidence of hidden or destructive behavior.

Before installing, confirm you are comfortable with the skill contacting financial/news services, using any configured proxy or Quotedance API key, running curl as a fallback, and keeping local market/news cache files. Treat the generated report as informational, not investment advice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are broad, generic finance terms such as '早报', '晚报', '今日市场', and '市场简报', which can overlap with ordinary user requests and cause the skill to activate when the user did not explicitly intend to invoke it. This creates an unintended invocation risk: the agent may route user queries into this skill automatically, leading to surprising behavior, unnecessary external data access, and reduced control over which capability handles the request.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal