A Stock Analysis 1.0.0

Security checks across malware telemetry and agentic risk

Overview

This skill appears benign: it fetches A-share market data and manages a local portfolio file, with a documented delete command that can remove local records.

Install only if you are comfortable sending queried stock symbols to Sina Finance and storing portfolio holdings locally in plaintext. Check stock code, cost, quantity, and intent before running add, update, or remove, because remove changes the local portfolio file without an undo mechanism.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill explicitly documents a destructive command to remove portfolio holdings but provides no warning, confirmation step, or recovery guidance. In a portfolio-management context, this can cause accidental deletion of user-maintained financial records, leading to loss of tracking data and incorrect P&L analysis.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal