Back to skill

Security audit

Financial Report Interpreter

Security checks across malware telemetry and agentic risk

Overview

This skill is a financial-report explanation helper with no network access, persistence, or transaction authority, but users should treat its finance guidance as informational only.

Install only if you want a local helper for interpreting financial reports and generating follow-up questions. Do not treat its ratios or stock-screening thresholds as personalized investment, tax, accounting, or legal advice, and avoid entering sensitive personal financial details unless you are comfortable with them being echoed in the tool output.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The README gives concrete stock-screening thresholds and 'buy before' style guidance aimed at retail investors, but does not warn that the content is educational or not financial advice. In this context, users may reasonably rely on the tool for investment decisions, creating a meaningful risk of misleading financial guidance and downstream user harm.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger language is broad enough to capture generic financial-planning and financial-advice requests, which can cause the skill to be invoked outside its stated scope of descriptive report interpretation. In a finance context, this scope creep increases the chance that users receive analysis or quasi-advisory output without appropriate safeguards, disclaimers, or boundaries.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill presents financial interpretation workflows, comparative company analysis, and stock-screening heuristics without an explicit warning that outputs are informational and may be incomplete, outdated, or inappropriate for investment decisions. Because users may rely on these outputs for board, corporate, or retail investing decisions, the absence of a clear caution materially raises the risk of harmful overreliance.

Missing User Warnings

Low
Confidence
91% confidence
Finding
The handler stores and returns an `original_input_preview` derived directly from raw user input, which may include sensitive financial details such as account amounts, debts, or other personal data. Even though this is only a preview and not external exfiltration, echoing user-supplied financial text increases unnecessary exposure in logs, downstream consumers, and UI surfaces.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.