Back to skill

Security audit

Bank Regulatory Reporting Assistant

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed banking regulatory report drafting skill with no executable code or hidden data access, though its activation phrases are broad.

Use this skill for draft preparation and checklist work only. Confirm the exact report type, jurisdiction, reporting period, and official source rules before relying on outputs, and have an authorized compliance officer review any report before filing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger list contains very generic phrases such as '监管报告', '合规报告', and '数据报送', which can activate this skill during ordinary banking or compliance conversations that are not actually asking for this specialized workflow. In a high-sensitivity domain like banking regulation, overbroad invocation can cause unintended collection, transformation, or drafting of regulated content, increasing the risk of misrouting user intent and producing compliance-relevant output in the wrong context.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.