Back to skill

Security audit

Banker Memo Md

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent prompt-and-helper package for generating a banker-style memo from user-provided local JSON data, with no hidden network, credential, persistence, or destructive behavior found.

Installation is reasonable if you intend to generate banker-style memos from local CN company raw-data JSON files. Before use, confirm the raw-data directory contains only data you mean to analyze, choose an output directory you are comfortable letting the agent write to, and review any resulting financial recommendations independently before relying on them.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.