Back to skill

Security audit

investment-banking

Security checks across malware telemetry and agentic risk

Overview

The skill matches its investment-banking purpose, but it can persist sensitive financial, deal, and regulatory drafts to Notion without a clear per-export consent step.

Review this skill before installing in any environment connected to Notion or containing client-confidential materials. Disable or tightly scope the Notion connector unless users explicitly approve each export, and treat all generated investment-banking drafts as requiring professional, legal, compliance, and confidentiality review before use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Description-Behavior Mismatch

Low
Confidence
79% confidence
Finding
The skill explicitly allows exporting financial models and valuation outputs to Notion, which can expose sensitive nonpublic financial data to an external service. In an investment-banking context, uploaded statements, forecasts, and deal assumptions may be highly confidential, so undocumented outbound data flow creates a real confidentiality risk.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The README states that users can 'say their needs' and the system will automatically match a sub-skill, while the listed trigger keywords are broad business terms such as IPO, M&A, and financial modeling. In a high-stakes investment-banking context, overly broad activation can cause unintended invocation of drafting or advisory workflows on ambiguous prompts, increasing the chance of incorrect routing, inappropriate disclosure handling, or generation of regulated content without sufficient user confirmation.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The routing logic allows activation based on broad scene descriptions rather than narrowly scoped, explicit user intent. In a high-impact investment banking skill, this can cause the agent to select and execute a sensitive workflow on ambiguous requests, leading to inappropriate generation of regulatory, financing, or M&A content without sufficient confirmation.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger phrases include common expressions such as requests to help write filings, build models, or prepare materials, which can overlap with many legitimate but unrelated business conversations. Because this skill operates in regulated financial contexts, overly generic triggers increase the risk of accidental invocation and production of formal-seeming compliance or capital markets content in the wrong context.

Missing User Warnings

Low
Confidence
90% confidence
Finding
The skill instructs writing generated bond-offering drafts into Notion, but it does not warn that these drafts may contain sensitive financial, issuer, deal-structure, or potentially non-public information. In an investment-banking context, exporting such material to a third-party knowledge base without explicit consent, data-classification checks, and connector-scope guidance can cause confidentiality breaches or unauthorized retention of regulated deal data.

Missing User Warnings

Medium
Confidence
85% confidence
Finding
The skill asks users to upload financial statements and may send results to an external knowledge base, but it gives no warning about sensitive financial data handling, external storage, or transmission. For investment-banking workflows, this omission materially increases the chance of accidental disclosure of MNPI, client financials, or regulated confidential information.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs writing regulatory response drafts and supporting materials to Notion, which can include highly sensitive IPO, audit, legal, and transaction documents. Sending such content to an external SaaS platform without an explicit user warning, consent gate, data-classification check, or minimization controls creates a real risk of confidential corporate, legal, and deal information being disclosed outside the intended trust boundary.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.