Back to skill

Security audit

Dailyfinance

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed daily finance briefing generator with optional scheduled delivery, and the reviewed files do not show hidden credentials, exfiltration, destructive actions, or unrelated privileges.

Install only if you want a skill that can generate finance-news HTML reports and, when explicitly enabled, schedule recurring pushes to Telegram, Feishu, Slack, or Discord. Review the userId, channel, and schedule before enabling push delivery, and treat the generated market content as informational rather than financial advice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Context-Inappropriate Capability

Medium
Confidence
96% confidence
Finding
The skill is presented as a news-briefing/dashboard generator, but it also documents operational push-management commands that can enable recurring delivery to external channels such as Telegram, Feishu, Slack, and Discord. This expands the capability from passive content generation into outbound messaging and scheduling, creating a materially different risk surface that could be abused for unsolicited messaging, data exfiltration, or persistence if an agent interprets these instructions as available actions.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The top-level description frames the skill as generating a financial dashboard, but the body also claims scheduling and multi-channel delivery behavior. This mismatch can mislead reviewers, users, or agent orchestration systems about the true privileges and side effects of the skill, increasing the chance that a more powerful operational capability is invoked under the guise of simple content generation.

Description-Behavior Mismatch

High
Confidence
95% confidence
Finding
The implementation materially diverges from the declared skill behavior: it includes unrelated vocabulary-theme scheduling logic and only emits a generic finance-search prompt rather than a clear daily finance push workflow. In an agent skill, this kind of spec/implementation mismatch is dangerous because it can conceal hidden behavior, mislead reviewers about what the skill actually does, and reduce trust in downstream automation that may rely on the manifest for access, routing, or safety expectations.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The keyword list is extremely broad and overlaps with many ordinary finance-related queries, which can cause the skill to activate in situations where the user did not specifically request this particular dashboard workflow. Over-broad activation is dangerous because the skill writes files and includes unrelated push-management documentation, so accidental invocation could trigger unexpected side effects or steer users into a more capable skill than intended.

Missing User Warnings

Low
Confidence
81% confidence
Finding
The skill instructs the agent to save an HTML file into user storage without any explicit disclosure or confirmation to the user. While writing a report artifact is consistent with the skill's purpose, silent file creation is still a side effect that can surprise users, create storage clutter, or normalize unannounced writes that become more dangerous if the skill later gains broader file or delivery capabilities.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.