Back to skill

Security audit

wealth-management

Security checks across malware telemetry and agentic risk

Overview

The skill is a coherent wealth-management assistant, but it handles sensitive financial client data and can write reports to Notion without clear consent, privacy, or retention controls.

Review before installing. This skill is not deceptive or destructive, but users should avoid uploading identifiable client financial data unless their organization permits it, and should require explicit confirmation before any Notion export or reusable model/risk-matrix update.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
The skill explicitly instructs the agent to 'update configuration model libraries and risk matrices' as part of post-task retrospection, which goes beyond generating a one-off wealth-management analysis or report. This expands the skill from bounded content generation into persistent process or knowledge modification, creating a pathway for unauthorized state changes, prompt drift, or contamination of reusable decision artifacts by untrusted user inputs.

Description-Behavior Mismatch

Medium
Confidence
83% confidence
Finding
The skill is primarily framed as a read/analyze workflow over user-provided fund reports, but it also introduces a Notion connector that can write analysis results into an external system. That expands the data flow and trust boundary: sensitive portfolio analysis, customer-related investment notes, or uploaded-report-derived content could be persisted or exfiltrated to a third-party workspace without the core skill description making those risks explicit.

Context-Inappropriate Capability

Medium
Confidence
71% confidence
Finding
Referencing a private-equity comparison skill inside a public-fund analysis workflow creates unnecessary capability expansion and role confusion. In a financial context, this can cause the agent to pull in analysis paths, assumptions, or products outside the declared scope, increasing the chance of unsuitable handling of investor data or unsupported recommendations for higher-risk products.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The activation guidance says users can trigger the skill through natural conversation, which makes invocation boundaries ambiguous and increases the chance the wealth-management workflow is activated during ordinary finance discussion. In a domain handling investment, tax, and client-reporting tasks, accidental activation can cause unintended processing of sensitive financial information or generation of advice when the user did not explicitly request it.

Vague Triggers

Medium
Confidence
89% confidence
Finding
Several trigger keywords are broad finance terms such as market overview, investment report, tax, and asset allocation, which are likely to appear in normal conversation and overlap across sub-skills. This can misroute user requests or invoke advisory/reporting functions without sufficient user intent, which is more sensitive here because the skill covers regulated financial recommendations and potentially confidential customer portfolio data.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger phrases are very broad and overlap with common financial requests, increasing the chance that unrelated or underspecified queries get routed into this skill automatically. In a financial-advice context, misrouting can cause the agent to apply the wrong template, request sensitive personal data unnecessarily, or produce investment/tax guidance without proper scoping or consent.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly states that client reports can be written to Notion, but it does not warn the user that sensitive financial portfolio data may be transmitted to and persisted in a third-party service. In a wealth-management context, this omission is more serious because the data includes identifiable client information, holdings, and performance details that may be regulated or confidential.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The workflow processes uploaded Excel/CSV portfolio data containing client financial details, but the skill provides no privacy notice, handling restrictions, or warning that the data may later be exported through connectors. In this context, undisclosed processing of sensitive investment data raises confidentiality, compliance, and unauthorized disclosure risks, especially if users assume the data remains local or ephemeral.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The optional connector section again says the client report and portfolio overview will be written to Notion, but still omits any privacy, consent, or third-party storage warning. Repeating this export behavior in a financial reporting skill without safeguards increases the chance of silent exfiltration or over-sharing of confidential client data to external collaboration systems.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.