Back to skill

Security audit

Finance Training Coach

Security checks across malware telemetry and agentic risk

Overview

This finance training skill is instruction-only and does not request code execution, credentials, persistence, or access to local or external data.

Installers should expect a bilingual finance-training assistant. Review the broad trigger wording if you use many other training or quiz skills, because ambiguous Chinese requests may activate this skill when a narrower finance-specific skill would be better.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger list includes very common Chinese terms such as '培训', '考核', and '测验', which are broad enough to match many unrelated user requests. This can cause the skill to activate outside its intended scope, leading to inappropriate instruction injection, response hijacking, or unintended handling of sensitive finance-related conversations.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The phrase '中文触发词(优先)' indicates a language preference that may bias activation and responses toward Chinese without explicit user choice. While not directly enabling code execution or data exfiltration, it can override user expectations, reduce reliability, and increase the chance of unintended prompt steering in multilingual contexts.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.