Back to skill

Security audit

Investment Advisor Digital Employee

Security checks across malware telemetry and agentic risk

Overview

The skill is a coherent financial-analysis assistant, but its manifest and capability notice understate external data/web access and report-file generation.

Review this skill before installing if your environment restricts outbound data access. It appears intended for professional financial analysis and requires human review, but administrators should align the manifest and capability notice with the actual external data, web retrieval, and generated-report behavior before broad deployment.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Intent-Code Divergence

High
Confidence
96% confidence
Finding
The skill claims there are no network calls, yet multiple modules explicitly instruct use of external data services and even web retrieval. This creates a trust-boundary mismatch: operators or downstream agents may approve or run the skill under false assumptions about data exfiltration risk, tool exposure, and compliance review requirements.

Intent-Code Divergence

Medium
Confidence
87% confidence
Finding
The skill says it only provides reference data and workflow guidance, but later directs the agent to generate Excel files and deliver reports. This is primarily a scope and transparency issue: users and reviewers may underestimate the degree of autonomous output generation and file production performed by the skill.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The manifest declares only data-analysis and reference-framework tools, but the skill text later instructs use of web_search and web_fetch as fallbacks. This hidden capability expansion is dangerous because it bypasses least-privilege expectations and can cause an agent to access external content that was not approved in the manifest or reviewed by administrators.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.