Back to skill

Security audit

Finxdata Skill

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed FinXData financial-data API helper that uses an API key and network calls for its stated purpose, with no evidence of hidden persistence, exfiltration, or destructive behavior.

Install this only if you want your agent to query FinXData. Configure the API key deliberately, be aware that finance queries may be sent to FinXData, and avoid setting FINXDATA_BASE_URL to an untrusted endpoint because the API key would be sent there for authenticated commands.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding
The skill instructs use of shell commands, environment variables, and outbound network access to a third-party API, but it does not declare corresponding permissions. Undeclared capabilities weaken least-privilege controls and reduce operator visibility into what the skill can access, increasing the risk of unintended secret exposure or unauthorized external requests.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill enables implicit invocation without any stated trigger boundaries, exclusions, or scope controls. That can cause the agent to invoke this finance-data skill unexpectedly on loosely related user prompts, increasing the chance of unintended data access, confused-deputy behavior, or unnecessary transmission of user context to an external API.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.