Back to skill

Security audit

OPC commercial canvas designer, financing consultant, Free Edition (Lite)

Security checks across malware telemetry and agentic risk

Overview

This text-only Lite business canvas skill has no executable code, but it asks for sensitive fundraising and financial details and blurs its stated Lite limits.

Review this carefully before installing. It is not a code-execution or exfiltration artifact, but users may share sensitive company finances, valuation expectations, investor progress, and legal/fundraising status with it. Install only if that expanded coaching scope and possible workspace-based profile retention are acceptable, and avoid entering confidential fundraising or legal details unless the platform gives clear controls for retention and deletion.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The template materially expands a 'Lite' business-canvas skill into broader fundraising-coaching workflows by collecting financing stage, target raise, valuation expectations, investor progress, due-diligence status, and agreement-review progress. This creates scope drift that can cause the agent to perform higher-risk advisory and persistent tracking tasks beyond the declared capability boundary, increasing the chance of inappropriate financial guidance and unnecessary retention of sensitive business data.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The file expands the Lite skill from simple business-model-canvas and BP skeleton generation into substantive investor-oriented BP coaching. This scope drift can bypass product/package boundaries, causing users to receive advanced fundraising guidance the manifest explicitly implies is not included in Lite, which is a trust and authorization problem even if it is not classic code execution.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
These sections explicitly direct the Lite skill to financial forecasting and fundraising-plan coaching, despite the manifest stating those capabilities require a Pro upgrade. This is more dangerous than generic scope drift because it enables unauthorized access to premium decision-support content and can materially affect fundraising, valuation, and financial-planning outcomes for users relying on the Lite tier.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.