fintech-engineer

Security checks across malware telemetry and agentic risk

Overview

This is a non-executable fintech engineering guidance skill, with broad high-impact subject matter but no hidden code, installer, credential access, or persistence.

Reasonable to install for fintech design and implementation assistance. For real payment, banking, trading, KYC/AML, or compliance work, require human approval, independent testing, rollback planning, and separate verification of any regulatory or certification claims.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill activates under the broad condition 'When invoked' without defining clear trigger boundaries, allowed inputs, or scope limits. In an agentic environment, this can cause the skill to be selected for loosely related requests and perform high-impact fintech, compliance, or transaction-processing guidance outside its intended context, increasing the risk of unsafe automation or misuse.

VirusTotal

53/53 vendors flagged this skill as clean.

View on VirusTotal