Back to skill

Security audit

plaid

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Plaid CLI helper for linking financial accounts and viewing balances or transactions, with sensitive but purpose-aligned access.

Install only if you trust the external plaid-cli dependency and are comfortable letting an agent access Plaid-linked financial data. Protect ~/.plaid-cli, avoid shared machines, prefer sandbox credentials for testing, and do not run plaid-cli tokens unless you intentionally want access tokens displayed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The example triggers are broad natural-language requests that can activate the skill for highly sensitive banking tasks without clear guardrails, confirmation requirements, or scope limits. In a finance skill, ambiguous activation increases the chance of unintended account access, transaction searches, or disclosure of sensitive financial data in response to loosely related prompts.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill notes that the data directory stores tokens and aliases, but it does not prominently warn users that sensitive Plaid tokens are persisted locally. Because these tokens can enable access to linked financial accounts, insufficient warning can lead users to store credentials on shared or insecure systems without understanding the risk.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.