Personal Finance & Wealth Intelligence

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed educational personal-finance skill with reference data only and no executable code, credential use, persistence, or hidden data handling.

Install only if you want an educational finance-planning assistant. Avoid entering unnecessary sensitive account details, treat outputs as informational rather than professional financial, tax, or legal advice, and consult a qualified fiduciary or other licensed professional before making major decisions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
Several triggers are generic consumer-finance phrases such as "retirement planning," "estate planning," "asset allocation," and "emergency fund," which are likely to appear in ordinary conversation and can cause unintended invocation. In a finance skill, accidental activation is especially risky because it may elicit sensitive personal financial information or produce overly specific planning guidance in situations where the user did not intend to engage this tool.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The file defines expansive personal finance reference content spanning investing, taxes, retirement, debt, and real estate, but it contains no embedded scope boundaries, activation constraints, or guardrails limiting when this material should be used. In an agent setting, that can cause over-broad invocation for generic money-related prompts and lead the system to provide financial-planning advice outside intended contexts, increasing the chance of inappropriate or overly authoritative recommendations.

VirusTotal

53/53 vendors flagged this skill as clean.

View on VirusTotal