Farmos Finance

Security checks across malware telemetry and agentic risk

Overview

This skill appears purpose-built for farm finance access, but it documents sensitive financial API access over plain HTTP and some unauthenticated integration endpoints, so users should review the deployment carefully before installing.

Install only if the API is on a trusted private network, the AI access toggle is intentionally enabled, and the unauthenticated endpoints expose only data you are comfortable allowing the agent to read. Prefer HTTPS and authenticated endpoints for financial data, and inspect the local farmOS auth script before allowing the agent to run it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
98% confidence
Finding
The skill documents highly sensitive financial endpoints over plain HTTP, including authenticated JWT-bearing requests and unauthenticated integration endpoints. This creates a serious risk of eavesdropping, token theft, and exposure or tampering of cash-flow, cost, and breakeven data by any party able to observe network traffic.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal