Trust Assessment
vibetrader received a trust score of 86/100, placing it in the Mostly Trusted category. This skill has passed most security checks with only minor considerations noted.
SkillShield's automated analysis identified 1 finding: 0 critical, 1 high, 0 medium, and 0 low severity. Key findings include High-Impact Financial Transaction Capabilities.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 12, 2026 (commit 13146e6a). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings1
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| HIGH | High-Impact Financial Transaction Capabilities The skill provides tools that allow the AI agent to perform real-money financial transactions (e.g., 'place_order', 'close_position') and manage trading bots (e.g., 'create_bot', 'delete_bot'). While these permissions are necessary for the skill's core functionality, they represent a significant risk. If the host LLM's decision-making is compromised (e.g., via prompt injection), it could lead to unauthorized financial actions, including buying/selling assets or manipulating trading strategies, potentially resulting in substantial financial loss for the user. The ability to switch to 'Live Trading' mode further amplifies this risk. Implement robust user confirmation mechanisms for all high-impact financial transactions, especially when in 'Live Trading' mode. Ensure that the LLM cannot execute these actions without explicit, unambiguous, and ideally multi-factor user approval for each specific transaction. Consider implementing spending limits, trade size restrictions, or daily transaction caps. Clearly communicate the financial risks to users before enabling live trading capabilities. | LLM | SKILL.md:58 |
Scan History
Embed Code
[](https://skillshield.io/report/0fc81c704bf5ee9d)
Powered by SkillShield