Back to skill

Security audit

Bank Financial Report

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only financial analysis skill with broad finance triggers, but no hidden code, data access, persistence, or automatic actions.

Install only if you want a conversational aid for financial statement review. Treat outputs as preliminary analysis, not audit assurance, legal/compliance advice, final lending approval, or investment advice; supervise use around confidential company financials and verify source data independently.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger list contains generic finance-analysis phrases such as 财务分析, 估值分析, and 财务报表分析 that are much broader than the stated bank-focused scope. This can cause the skill to activate for many ordinary finance requests, increasing the chance of unintended routing, user confusion, and application of bank-specific guidance in contexts where it may not fit.

Vague Triggers

Low
Confidence
80% confidence
Finding
The usage section says users can 'just paste financial statement data and tell me what analysis you need,' without clearly limiting the skill's operational boundaries. In a multi-skill or automated routing environment, this broad invitation can encourage use for adjacent high-risk tasks like audit conclusions, lending decisions, or regulated advice despite later disclaimers.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.