Back to skill

Security audit

Finance

Security checks across malware telemetry and agentic risk

Overview

This finance skill is non-executable, but it makes sensitive financial, compliance, popularity, and broad ecosystem-install claims that users should review carefully before trusting.

Install only if you are comfortable treating it as unverified finance guidance. Do not provide banking credentials, full account numbers, tax IDs, or unnecessary financial records, and review any invoice, investment, budget, or tax output with a qualified human before acting. Do not run the separate ecosystem installer unless you have independently reviewed those additional skills and their memory/orchestration behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
This finance skill advertises handling expenses, invoices, budgeting, investments, and tax optimization, but it does not clearly warn users about the sensitivity of financial data or the operational risks of automated invoicing and financial recommendations. In a finance context, missing disclosures can lead users to provide bank, tax, vendor, or portfolio data without understanding privacy, authorization, or downstream action risks, increasing the chance of harmful misuse or unsafe reliance.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.