Back to skill

Security audit

Earnings Call AI Analyst

Security checks across malware telemetry and agentic risk

Overview

This finance-analysis skill is purpose-aligned and disclosed, with no executable code, persistence, credential harvesting, or hidden data handling found.

Install only if you want an educational earnings-call and filing summarizer. Verify all extracted numbers and quotes against official filings before using the output, and do not treat its sentiment scores or red-flag interpretations as personalized investment advice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger list contains broad phrases such as 'conference call', 'earnings summary', and 'SEC filing summary' that can match many normal finance queries outside the skill’s intended scope. This can cause unintended invocation, leading the system to fetch or analyze unrequested financial documents and produce high-confidence financial commentary in contexts where the user did not explicitly ask for this workflow.

Vague Triggers

Low
Confidence
82% confidence
Finding
The invocation guidance says when to invoke the skill but does not define when not to invoke it, even though the skill can process transcripts, SEC filings, and links from multiple sources. Without exclusion boundaries, the agent may activate this skill for adjacent requests such as generic SEC-document summarization or broader market questions, increasing the chance of scope creep and misleading outputs.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.