Back to skill

Security audit

Commercial Credit Memo Drafter

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed commercial credit memo drafting skill that handles sensitive borrower information but does not run code, persist data, or make binding credit decisions.

Install only if you are comfortable entering confidential borrower, guarantor, and credit-policy information into your agent session. Treat every output as a draft analytical memo for qualified human review, not as an actual credit approval, legal decision, or compliance determination.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The skill metadata says it produces an Approve/Approve-with-conditions/Decline recommendation, while the body says it must never approve, decline, or commit to credit, only that recommendations are advisory. This contradiction can cause downstream agents or users to rely on the skill for quasi-credit decisions despite the stated boundary, which is risky in a regulated lending workflow.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
Within the skill itself, 'Never approve, decline, or commit to credit' conflicts with later required output options that include 'Approve as proposed' and 'Decline' in the recommendation section. In a credit context, this ambiguity can lead an autonomous agent to present a decision-like output as authoritative, increasing legal, compliance, and operational risk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.