Watch My Money
PassAudited by VirusTotal on May 14, 2026.
Findings (1)
The skill is designed for local financial analysis, explicitly stating 'privacy: local-only' and 'no network calls' for transaction data in SKILL.md. File system interactions are limited to saving state and reports in `~/.watch_my_money/`, which is a standard practice for local applications. The `assets/template.html` loads a font from Google Fonts, which is a benign network call for styling and does not involve data exfiltration or malicious execution. There is no evidence of prompt injection attempts against the agent, malicious execution, persistence mechanisms, or obfuscation.
