Back to skill

Security audit

Financial Model Forecast Reviewer

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only financial model review helper, with a broad trigger scope but no hidden code, persistence, credential handling, or destructive behavior.

Before installing, be aware that this skill may activate for broad finance or business-planning language. It appears safe as a documentation-only helper, but users should still avoid sharing sensitive company financials unless needed for the specific task.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger sentences are broad, awkwardly phrased, and map to common business/finance language, which can cause the skill to activate outside the author's intended scope. Overbroad activation is dangerous because it can route unrelated prompts into this skill, leading to unintended instruction precedence, confusion, or misuse of financial guidance in contexts where it was not requested.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrases are broad, generic, and include a direct invocation pattern that could cause the skill to activate in contexts where the user did not specifically request this capability. Overbroad activation increases the chance of inappropriate routing, context hijacking, or accidental use of a specialized finance workflow on unrelated requests, which can degrade trust and produce unsafe or misleading business guidance.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill description is framed broadly enough that it could activate on many general business or planning requests, not just financial-model review tasks. Overbroad routing can cause the agent to apply the wrong workflow, collect unnecessary business-sensitive data, or produce misplaced financial guidance in contexts where a more appropriate skill should handle the request.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger keywords are generic business terms like 'forecast', 'runway', and 'assumptions', which are likely to appear in many unrelated conversations. This increases the chance of accidental invocation and inappropriate context capture, making the system easier to steer into using this skill when it is not the best or safest match.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The description says to use the skill for broad categories like 'business-and-operations' plus several finance-related terms, but it does not define clear activation boundaries. This ambiguity increases the chance of over-selection by routing systems or agents, which may invoke the skill for generic operational questions and produce mismatched or overconfident outputs.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger keywords are broad business terms such as 'forecast', 'runway', and 'assumptions', which can appear in many ordinary conversations unrelated to this specific skill. That can cause unintended activation, leading the agent to apply specialized financial-review behavior in contexts where it is not appropriate, reducing reliability and potentially steering user workflows incorrectly.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill enables implicit invocation while using a very broad default prompt covering generic financial-model and business-planning tasks. This can cause the agent to invoke the skill in situations the user did not clearly request, increasing the chance of over-collection of sensitive business data, unintended delegation, or user confusion about which component is acting.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The trigger sentences and keywords are broad enough to match many generic business or finance requests, which can cause the skill to activate outside its intended scope. Over-broad activation increases the chance of misrouting user tasks, causing inappropriate handling of sensitive financial planning requests or suppressing better-matched skills.

Natural-Language Policy Violations

Low
Confidence
86% confidence
Finding
This zh-CN README contains substantial English instructional text and English trigger phrases, which can impose a language expectation without user opt-in. The file does not indicate that users may choose Chinese or English for interaction in this localized documentation.

Natural-Language Policy Violations

Low
Confidence
82% confidence
Finding
该技能文件整体以中文(zh-CN)呈现,且未说明这是可选本地化版本或允许用户选择其他语言。按照语言/区域政策,若技能对输出语言形成默认强制而没有明确 opt-in,可能构成自然语言策略问题。

Static analysis

No suspicious patterns detected.