Back to skill

Security audit

Accountant

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed local accounting skill that keeps bookkeeping notes in named local folders and shows no hidden code, network transfer, or credential capture.

Install this only if you want the agent to maintain local Clawic accounting notes, including shared finance and contact boxes. Consider setting work-order or restriction preferences for confirmation before postings, write-offs, locked-period changes, or other high-impact bookkeeping updates.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Low
Confidence
89% confidence
Finding
The skill explicitly instructs the agent to write durable records into user-controlled files such as policy documents, open-items memory, contacts, and ledger-related artifacts without an explicit confirmation or persistence warning. While this appears operationally intended for an accounting skill, it still creates a real risk of unintended persistent data modification, especially because the writes may affect financial records, workflow state, or contact data.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The file explicitly instructs the agent to make durable changes to user finance records such as accounts.md, subscriptions.md, and open items, but it does not require confirmation, preview, validation, or backup before modifying those files. In a bookkeeping context, silent persistence is risky because an incorrect reconciliation note, account creation, or write-off trail can corrupt financial records and propagate into reporting, tax, and audit workflows.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.