Back to skill

Security audit

Credit Risk Manager Digital Employee

Security checks across malware telemetry and agentic risk

Overview

This banking risk-analysis skill is broadly purpose-aligned, but it under-discloses sensitive bank-system access, external lookups, and multi-year audit-log retention.

Review before installing. Use only in a controlled banking environment after explicitly approving the external data sources, internal API scopes, credit-bureau authorization flow, audit-log contents, retention period, and access controls. Do not rely on the top capability notice as an accurate summary of what the skill asks the agent to do.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
The top-level notice claims the skill has no network calls or persistent storage, but multiple modules later instruct external searches/API access and retention of audit logs for years. This creates a dangerous trust mismatch: operators or governance systems may approve the skill under false assumptions while it actually handles external data flows and stored records.

Intent-Code Divergence

High
Confidence
98% confidence
Finding
The document says there is no persistent storage or credential collection, yet later modules require creation of audit files containing operator identity, customer identifiers, and execution metadata retained for 3 years. This can cause unauthorized retention of sensitive banking and employee data, and the contradiction may bypass privacy review because the skill presents itself as storage-free.

Context-Inappropriate Capability

High
Confidence
95% confidence
Finding
The skill is framed as a 'knowledge reference framework' with limited allowed tools, but the body instructs access to broad internal banking systems, payment flows,征信, collateral, group exposure, and other sensitive sources. That mismatch can lead to over-privileged deployment or unsafe operator trust, especially if enforcement relies on the declared tool/capability metadata rather than the full content.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.