Back to skill

Security audit

Copilot Money Skill

Security checks across malware telemetry and agentic risk

Overview

This finance skill is not shown to be malicious, but it needs review because it can use a CLI to read a local browser session token for sensitive Copilot Money data.

Install only if you trust the publisher and the copilot-money-cli package. Treat it as access to your Copilot Money account: it may read a browser session token and retrieve sensitive financial data. Prefer explicit prompts, require confirmation before any refresh/sync action, and revoke the browser session if you no longer want the tool to have access.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill description is broadly scoped to activate on many finance-related requests, including sensitive topics like balances, transactions, net worth, and bank refresh actions. Overly broad routing for a finance skill increases the chance the agent invokes a tool handling highly sensitive financial data when the user did not explicitly intend to use this specific integration, creating privacy and unintended-action risk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.