Back to skill

Security audit

Investment Research

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed finance research template suite that processes user-provided materials and optionally writes reports to Notion only after asking the user.

Install only if you are comfortable using it for financial research drafts. Review outputs independently before relying on them, avoid uploading restricted or inside information unless your organization permits it, and confirm destination and permissions before allowing any Notion write-back.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The README says users can trigger sub-skills through natural conversation and automatic matching, but it does not define strong disambiguation or confirmation boundaries. In a finance workflow, broad NL routing can cause the wrong research template to activate, leading to unintended document processing, incorrect outputs, or accidental handling of sensitive research materials.

Vague Triggers

Medium
Confidence
88% confidence
Finding
Several trigger terms in the routing table are generic finance phrases such as '晨会', '行业研究', '公司深度', and '10-K', which are likely to appear in normal discussion without an actual request to run the skill. This increases the chance of accidental invocation or misrouting, especially in analyst chats where these terms are common and may refer to context rather than an instruction.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill advertises broad trigger phrases such as generic finance/research requests, which can cause the skill to activate in situations the user did not explicitly intend. In an agent setting, overbroad invocation can route unrelated user data into this workflow, causing incorrect task execution, unintended file reads from the references directory, or confusing/unsafe autonomy.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The skill metadata and instructions are written to enforce Chinese-language behavior without checking the user's language preference. This can override user expectations, reduce transparency, and increase the chance that the user misunderstands outputs, disclaimers, or requests for confirmation, especially in a financial-analysis context where precision matters.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.