Back to skill

Security audit

candor-finance

Security checks across malware telemetry and agentic risk

Overview

This is a coherent personal-finance skill, but it gives an agent broad access to sensitive financial data and permits persistent notes, background checks, and some record changes without clear per-action user confirmation.

Install only if you are comfortable giving Candor and your agent ongoing access to sensitive financial records. Before enabling it, confirm how to review, edit, and delete Candor notes, impacts, transaction corrections, rules, and the background monitoring job, and require fresh confirmation for bulk edits or any action that changes external accounts, payments, trades, filings, cancellations, or messages.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill advertises itself for essentially any task that 'touches the user's money, financial records, prior decisions, or approved plans,' which is an unusually broad activation scope for a high-sensitivity domain. In practice this can cause the agent to invoke the skill in many contexts involving financial data and normalize broad access to sensitive records, increasing the chance of over-collection, overreach, or unintended autonomous handling of financial matters.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The workflow directs the agent to create a timed note containing source references, evidence handles, expected windows, and caveats, but it does not require notifying the user that this information will be stored or obtaining explicit consent first. In a finance-and-benefits skill, those notes can contain sensitive health, reimbursement, and financial metadata, creating privacy and data-retention risk beyond what the user may expect from a one-time reimbursement check.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The workflow instructs the agent to persist a planned expense as a durable note after a coverability check, but it does not require an explicit user-facing consent step or warning that this creates stored financial planning state. In a finance skill, silently retaining planned purchases and their projected effects can violate user expectations, propagate stale assumptions into later projections, and create privacy risk because future answers may reuse sensitive intent the user did not realize was being saved.

Missing User Warnings

Low
Confidence
95% confidence
Finding
The workflow directs the agent to create and later resolve persistent notes containing sensitive financial details, search history, account-safe identity, and action IDs, but it does not require any user-facing notice or consent before writing that record. In a personal-finance skill, silently persisting unresolved income investigations increases privacy and data-retention risk because users may not expect durable storage of detailed financial observations and follow-up instructions.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
This workflow explicitly allows the agent to modify financial transaction data based on inferred existing task authority, without a fresh, explicit confirmation at the point of change. In a finance context, even reversible edits can misclassify records, distort budgets or tax-related reporting, and cause the agent to overstep the user's intent when the scope of authorization is ambiguous.

Missing User Warnings

High
Confidence
99% confidence
Finding
The workflow permits bulk application of rules across multiple transactions when the system decides the current task already grants authority, and it specifically says not to ask again for approval. In a personal-finance skill, bulk edits can silently propagate a mistaken interpretation across many records, causing widespread corruption of categories, budgets, spending analysis, and downstream financial decisions.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The workflow explicitly directs the agent to persist notes containing transaction baselines, merchant variants, expected price windows, coverage details, and query action IDs, which are sensitive financial records and behavioral metadata. In a personal-finance skill, storing this data without an explicit minimization rule, retention limit, or user-facing consent/notice increases the risk of unnecessary long-term exposure if notes are later accessed, reused, or leaked.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The recipe instructs the agent to set up unattended, authenticated financial monitoring after a single user prompt, but it does not require an explicit warning about the privacy, persistence, and account-access implications of background execution. In a finance skill, silent recurring access to sensitive records increases the risk of user surprise, overbroad consent, and unnoticed exposure if the scheduler or authenticated environment is compromised or misconfigured.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.