Back to skill

Security audit

Fintech Research

Security checks across malware telemetry and agentic risk

Overview

The skill is a coherent finance research toolkit, but it needs Review because it exposes an unrestricted local SQL tool and can produce investment recommendations from cached or synthetic data without enough safeguards.

Install only if you are comfortable with a local finance MCP server making outbound requests to public market-data providers and writing local research artifacts. Treat outputs as research drafts, not personalized investment advice; verify live data sources, watch for mock:true results, and avoid enabling unrestricted SQL or file-modifying workflows in sensitive workspaces unless you can supervise them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (22)

Lp3

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding
The skill advertises network use and environment variables in metadata, but the finding indicates those capabilities are not explicitly declared as permissions. That creates a transparency and trust problem: users may install or invoke the skill without understanding it can access external services and local secrets, which increases the risk of unintended data exposure or policy bypass in environments that rely on declared permissions.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
The documented behavior does not fully match the implemented capabilities, especially the presence of a SQL execution tool, undisclosed synthetic fallback data, and additional utilities not described in the overview. This is dangerous because hidden or under-disclosed capabilities can be abused by prompts or downstream agents to access or manipulate local cached data, while mock data can mislead users into making decisions based on fabricated outputs they believe are real.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
The skill explicitly directs the agent to produce a publication-ready equity research report including a price target, recommendation, and institutional-quality investment thesis. That goes beyond neutral research/data retrieval and into personalized or actionable investment recommendation generation, which can mislead users into relying on AI-produced financial advice without appropriate controls, disclosures, or suitability checks.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The function catches any unexpected exception and silently returns mock disclosure data, which can cause callers to treat fabricated or stale data as real market disclosures. In a fintech research context, this undermines data integrity and can mislead downstream analysis, alerts, or investment decisions without any clear signal that the live fetch failed.

Intent-Code Divergence

High
Confidence
99% confidence
Finding
The `run_sql` tool claims to be read-only but passes arbitrary user-supplied SQL directly to SQLite without enforcing `SELECT`-only behavior or opening the database in read-only mode. Any MCP client able to call this tool can modify or delete cached data, alter schema, or potentially attach other databases/files depending on SQLite capabilities, which breaks integrity guarantees and can be chained into broader misuse of the local environment.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger list contains generic phrases like 'analyze,' 'monitor,' and 'track' that are common in ordinary conversation, which can cause unintended routing into powerful research workflows. In an agent skill context, overbroad invocation increases the chance of accidental external data access, unintended tool use, and execution of a workflow the user did not explicitly request.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The README repeatedly states that Claude will automatically detect the local MCP server and fetch data from external sources such as yfinance, HKEX, FRED, NewsAPI, RSS, and SEC EDGAR, but it does not clearly warn users that prompts, tickers, search terms, and optional API credentials may result in outbound network requests. In an agent skill context, this matters because users may assume analysis is local/self-hosted while the workflow actually causes network access to third-party services, creating privacy, compliance, and data-handling risks.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The README states that users can invoke skills through broad natural-language phrases and that a dispatcher will automatically route requests based on intent mapping. In an agent setting, overly permissive trigger matching can cause accidental invocation of finance-research workflows from ordinary conversation, which may initiate unintended data access, external requests, or misleading task execution without clear user confirmation.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger list includes broad natural-language phrases such as 'find ideas', 'new ideas', 'what looks interesting', and 'screen for', which can overlap with ordinary user conversation and cause the skill to activate unexpectedly. In this context the skill is finance-focused rather than directly executing code or handling secrets, so the main risk is misrouting, unintended tool use, or noisy/inappropriate activation rather than a severe compromise.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill directs the agent to read existing local files and create or modify `.docx`, `.xlsx`, image, and zip outputs using actual file operations, but it does not require explicit user confirmation of write locations or warn that local files will be altered. In an agent environment with filesystem access, this can lead to unintended overwrites, modification of sensitive working files, or writing outputs into unsafe paths based on ambiguous context.

Missing User Warnings

Low
Confidence
80% confidence
Finding
The workflow instructs the agent/user to create and save local Excel files containing company financial data, including potentially sensitive private-company statements, without any warning, consent checkpoint, storage guidance, or data-handling controls. In a fintech research skill, this increases the risk of unintended local persistence of confidential data, accidental disclosure, and mishandling of non-public financial information.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The workflow explicitly instructs the agent to modify an existing Excel financial model file in place, but it does not require obtaining user confirmation, creating a backup, or warning that user data will be changed. In an agent setting, this can lead to unintended overwrite or corruption of a user's working financial model, especially if the workbook contains formulas, links, or manual adjustments beyond Task 2 output.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The workflow directs the agent to create and save a DOCX output and manipulate local files without any explicit user-facing notice or confirmation about filesystem writes. Silent file creation/modification can surprise users, overwrite existing work, or normalize broader unsupervised local actions by the agent.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill instructs extraction of a zip archive into a working directory without warning or consent around filesystem changes. Archive extraction is riskier than ordinary file reads because it can create many files, consume disk space, overwrite paths, or, if not safely handled, introduce path traversal issues from crafted archive contents.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrase "management" is overly broad for an auto-invoked skill because it can match many ordinary user requests unrelated to equity research, causing unintended activation. In an agent setting, ambiguous routing increases the chance the model follows the wrong workflow, performs unnecessary data access or external tool calls, and produces irrelevant or misleading analysis.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger list contains generic everyday terms such as "jobs" and "wages" that can match many unrelated user requests, increasing the chance this skill is invoked unintentionally. In an agent setting, over-broad invocation can route users into the wrong workflow, causing irrelevant data access, noisy outputs, and reduced trust in system behavior, though the direct security impact here appears limited because the skill only performs market-data retrieval and analysis.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger list includes very common finance terms such as "rates," "Fed," and "yield curve," which can cause the skill to activate in contexts broader than intended. That increases the chance of unintended tool use and irrelevant financial data retrieval, especially in multi-skill environments where routing is based on keyword matches.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill advertises activation on broad phrases such as "themes," "market themes," and especially "what's working," which are common user expressions and can cause the skill to trigger unintentionally. In an agent setting, overly broad routing can lead to misfires, unexpected tool use, and disclosure of financial-analysis outputs when the user did not explicitly request this skill.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger list includes very generic phrases such as "events" and "what's coming," which can cause the skill to activate in unrelated conversations. In an agent setting, over-broad invocation can route user requests into the wrong workflow, leading to unintended data access, confusing outputs, or unnecessary external calls.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger list includes broad phrases like "conviction" and "still hold," which can appear in ordinary financial discussion and unintentionally invoke this skill. In an agent setting, overly broad activation can cause the assistant to fetch market data or begin portfolio-oriented analysis when the user did not explicitly request a thesis review, creating unintended tool use and confusing or misleading responses.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger list includes very generic phrases such as "track" and "add ticker" that can appear in ordinary conversation, increasing the chance this skill activates when the user did not explicitly intend to use it. In an agent setting, unintended activation can cause unexpected state changes to a persisted watchlist or unnecessary external data access, making this a real prompt/skill routing weakness even if it is not overtly malicious.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The documentation explicitly advertises a tool that executes arbitrary SQL against a local SQLite database, with no indication that it is restricted to read-only statements or guarded against destructive queries. In an agent context, this materially increases risk because an LLM or prompt-injected workflow could issue DELETE, UPDATE, DROP, ATTACH, or PRAGMA statements that corrupt cached data, alter analysis outputs, or access unexpected local files through SQLite features.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.