Back to skill

Security audit

A Share Portfolio

Security checks across malware telemetry and agentic risk

Overview

This portfolio-analysis skill handles sensitive holdings data, but its behavior is disclosed, purpose-aligned, and not persistent or destructive.

Install only if you are comfortable discussing portfolio holdings, cost basis, and purchase timing in the chat. Avoid sharing broker logins, account numbers, or unnecessary personal identifiers, and review the separate cn-stock-data helper before relying on its market-data behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger list includes broad everyday phrases such as '帮我看看组合' and '风险分析', which can cause the skill to activate in contexts where the user did not intend to share or analyze sensitive portfolio data. In this skill context, accidental invocation is more concerning because it handles personal holdings and financial information, increasing the chance of inappropriate data collection or overly specific financial analysis being launched without clear consent.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.