Back to skill

Security audit

Training Finance

Security checks across malware telemetry and agentic risk

Overview

This skill is a simple student and training finance worksheet prompt, with expected but sensitive student and payment data handling.

Before installing, treat this as a tool for handling private student and payment information. Use only necessary fields, avoid sharing full contact or payment details in broad prompts or reports, and verify all financial calculations in your approved accounting process before acting on them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly processes personally identifiable information and financial data, including names, organizations, contact details, payment status, and invoice information, but provides no privacy, minimization, retention, masking, or access-control guidance. In a workflow that centralizes student management and finance, this omission can lead users to expose, over-collect, or improperly share sensitive records in prompts, reports, or logs.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.