Back to skill

Security audit

Financial Engineer Digital Employee

Security checks across malware telemetry and agentic risk

Overview

The skill appears aimed at legitimate financial modeling work, but it needs Review because it says it does not store anything while its workflows write reports, logs, models, and other artifacts to disk.

Review before installing. Only run it on datasets you are authorized to use, choose explicit output directories, set max rounds and compute limits, and delete generated reports/models/logs when they may contain sensitive or regulated data. Treat all model outputs as draft analytical artifacts requiring qualified human review before business use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The capability notice materially misrepresents what the skill does. It claims to be only a knowledge/reference framework, but the rest of the file documents active execution of profiling, training, tuning, model serialization, and deployment-oriented artifact generation, which can mislead operators, reviewers, and policy enforcement into granting the skill more trust or broader access than warranted.

Intent-Code Divergence

High
Confidence
99% confidence
Finding
The file explicitly claims 'No persistent storage' while repeatedly instructing the system to write reports, models, logs, JSON manifests, and other outputs to disk. This contradiction can bypass user expectations and control assumptions around data retention, causing sensitive datasets, model artifacts, or derived intelligence to persist on the filesystem unexpectedly.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The tuning trigger phrases are broad enough to match ordinary conversation such as '调参' or '优化一下', increasing the chance that the skill activates high-impact tuning workflows unintentionally. In this skill, activation is not low-risk: it can launch iterative model-training behavior, write artifacts, and consume significant compute, so ambiguous routing meaningfully raises the chance of unintended execution.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The autonomous experiment module advertises activation from vague exploration requests without strong scope limits, which can lead to broad, self-directed experimentation over user data. Because this module can iteratively train models, test many hypotheses, and generate multiple artifacts, ambiguous invocation increases the risk of runaway compute use, unintended data processing, and actions beyond the user's actual intent.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.