Back to skill

Security audit

Financial Tracker

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent Convex component-building guide with expected code-editing and validation steps, and no evidence of hidden or unrelated behavior.

Install this if you want an agent to help design and implement Convex components. Review generated backend code before deployment, especially component schemas, scheduled callbacks, app wrappers, environment-variable handling, and any webhook or package-publishing configuration.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The month-end automation performs state-changing file writes across multiple finance artifacts and can send an outbound notification, but the pattern does not include explicit consent, preview, or confirmation controls. In a financial-tracking skill, silent modifications to summaries, state files, and tax estimates can create integrity and privacy risks if triggered unexpectedly, misconfigured, or pointed at the wrong recipient.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.