Back to skill

Security audit

Credit Review Digital Employee

Security checks across malware telemetry and agentic risk

Overview

The skill is broadly aligned with credit review, but it under-discloses sensitive API access, stored notes/audit logs, and workflow-gating behavior in a high-stakes banking process.

Review this skill carefully before installing. It should be treated as an operational credit-review assistant that may access sensitive customer, credit, banking, public-record, and collateral data, and may create retained notes or audit records. Use it only where those data flows, retention rules, and human approval controls are explicitly authorized.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The skill advertises 'no persistent storage' while multiple modules explicitly instruct saving reports, notes, and audit logs with multi-year retention. This misrepresentation can defeat user and platform trust boundaries, causing operators to disclose sensitive financial and personal data under false assumptions about data handling.

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
The header claims there are 'no network calls,' but the skill repeatedly instructs use of internal APIs, external data interfaces, web search, and system queries. In a credit-review context, these calls can expose regulated customer data to systems the user may not expect, making the false claim materially dangerous.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The skill claims to be only a reference framework, yet it directs operational actions such as gating case intake, saving customer notes, generating audit artifacts, and producing pass/fail workflow outcomes. This creates a dangerous mismatch between stated and actual authority, encouraging reliance on automated workflow decisions in a high-stakes banking process.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.