Back to skill

Security audit

Variance Analyst

Security checks across malware telemetry and agentic risk

Overview

This is a finance reporting skill that analyzes user-provided budget variance data and shows no hidden code execution, persistence, or external data transfer.

Before installing, be aware that the skill is intended for potentially confidential financial data, so use it only in sessions where that data is appropriate to share. Specify currency and materiality thresholds if USD or the default threshold is not suitable.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Low
Confidence
92% confidence
Finding
The markdown instructs the skill to default to USD unless the user specifies otherwise. This imposes a locale-related default without first offering a choice or requiring confirmation, which can conflict with policy guidance against forcing a specific locale without opt-in.

VirusTotal

54/54 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.