Back to skill

Security audit

Wealth Copilot Digital Employee

Security checks across malware telemetry and agentic risk

Overview

This financial-advisor skill is broadly coherent, but it says there are no network calls while directing sensitive client financial data through remote MCP services.

Review this before installing in any environment handling real client data. Confirm which MCP providers receive customer information, require consent and minimization for KYC and portfolio fields, and avoid using identifiable client records until the no-network disclosure and report-export controls are corrected.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Intent-Code Divergence

High
Confidence
99% confidence
Finding
The skill explicitly claims there are no network calls, yet the body repeatedly instructs use of remote MCP endpoints over HTTPS. That mismatch can mislead users and reviewers about actual data flows, especially because the skill handles sensitive financial and customer KYC information. In this context, the contradiction increases risk because operators may disclose regulated client data under a false assumption of local-only processing.

Context-Inappropriate Capability

Medium
Confidence
78% confidence
Finding
The skill includes PDF report generation despite being declared as a knowledge/reference framework with only 'data-analysis' and 'reference-framework' tools allowed. Expanding into document generation can create unreviewed output/export pathways for sensitive household financial data and may bypass expected governance or retention controls. In a wealth-management context, generated reports may contain highly sensitive PII and financial profiles.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill expects sensitive client data via context injection, including identity, family, holdings, income, assets, liabilities, and risk profile, and then routes analysis to external MCP services. The documentation mentions privacy in a general sense but does not clearly warn users that this data may be transmitted to third-party endpoints. Given the regulated financial-advice setting, undisclosed external transmission of KYC and portfolio data creates substantial privacy, compliance, and confidentiality risk.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.