Corporate Credit Memo

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed credit-memo drafting skill that processes user-provided financial documents and public web research, with no evidence of hidden code, credential use, persistence, or destructive behavior.

Install only if your organization permits AI-assisted handling of borrower financial statements and deal terms. Treat the generated memo as a draft for qualified credit, legal, compliance, and risk review, and avoid sending confidential facility details through web-search queries.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger description is very broad and includes many common phrases for loan, borrower, and credit-analysis work. That can cause the skill to activate for requests that only partially match the intended use case, increasing the chance of unsolicited web research, document processing, or generation of formal lending outputs when the user wanted lighter-weight analysis.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal