Back to skill

Security audit

Finanças Donna

Security checks for vulnerabilities and agentic risk

Overview

This personal finance skill is not malicious, but it should be reviewed because it can read and update sensitive finance files from very broad trigger words and contains one person's private financial context.

Install only if this is meant for Evandro's own finance workspace or after replacing the personal rules with your own. Use it with backed-up finance files, narrow the activation triggers if possible, and require explicit confirmation before any financial file is read or changed.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill declares automatic activation on very broad finance-related terms such as common verbs and category words, which can cause the agent to load and apply financial-file reading or update logic during ordinary conversation. In this context, overbroad triggering increases the chance of unintended access to sensitive financial data or accidental modification flows without sufficiently explicit user intent.

Vague Triggers

Medium
Confidence
89% confidence
Finding
Using generic file-processing triggers like 'fatura', 'extrato', 'cartão' and 'banco' can invoke the skill in many unrelated contexts, especially because the skill then instructs the agent to read financial files and process documents. That creates a realistic risk of unintended handling of banking/card materials or scope creep into sensitive documents without clear, explicit authorization.

Natural-Language Policy Violations

Low
Confidence
81% confidence
Finding
The skill is explicitly built around a named individual and embeds highly specific personal relationships and financial rules, which can cause the agent to apply one person's private assumptions to whoever triggers the skill. In a shared or reused environment, this creates privacy and integrity risks by exposing personal context and by misclassifying another user's financial data based on hard-coded identity-specific logic.

Static analysis

No suspicious patterns detected.