Back to skill

Security audit

CFO / Chief Financial Officer

Security checks across malware telemetry and agentic risk

Overview

This CFO skill is a disclosed local guidance tool that stores limited preferences/context and does not connect to accounts, move money, or run code.

Before installing, understand that this skill may remember CFO preferences and company context locally and may proactively surface cash-runway or cost-cut advice. Do not store secrets, account details, raw bank/payroll exports, or legally sensitive decisions in its memory; keep major finance, legal, tax, employment, and payment actions under human and professional review.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The line ties automatic opening of this skill to a configurable runway threshold (`runway_alert_months`), which can cause the skill to activate without clear user intent or contextual confirmation. In a finance workflow, unintended invocation can steer decisions during sensitive cash-crunch situations and may surface aggressive restructuring guidance at the wrong time.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs the agent to persist user-derived preferences and context into local files without requiring explicit user consent at the time of write or any user-facing notice that local state will be modified. Even though it excludes highly sensitive categories, it still authorizes silent persistence of business context across sessions, which can surprise users, retain confidential operational information longer than intended, and create privacy/integrity risks if the stored files are later accessed or reused incorrectly.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.