Back to skill

Security audit

短线手术刀 (ScalpelTrade)

Security checks across malware telemetry and agentic risk

Overview

This stock-analysis skill does not show malware or credential theft, but it provides trading decision support while downplaying that role and uses plaintext HTTP for some market data.

Install only if you understand it is a trading decision-support tool, not just a data formatter. Treat its recommendations, position limits, and tracking outputs as unverified analysis, and be cautious because some market data is fetched over plaintext HTTP.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The compliance statement says the skill only organizes market data and computes indicators, but the rest of the document clearly describes recommendation generation, debate-based decisioning, risk audits, and recommendation tracking. This mismatch can mislead reviewers and users about the skill’s actual behavior and decision-support role, reducing informed consent and weakening governance controls.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The finding is valid because the code explicitly uses plaintext HTTP URLs for Eastmoney data retrieval while the docstring normalizes this by saying it has 'no SSL dependency'. In a financial data collection skill, this makes market data vulnerable to man-in-the-middle tampering or passive interception, which could corrupt trading signals and downstream decisions.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.