Back to skill

Security audit

Analyze Creator Financial Health with Automated Reporting

Security checks across malware telemetry and agentic risk

Overview

The skill is coherent for financial reporting, but it asks for live payment and business-service credentials without enough scoping or secret-handling guidance.

Review this skill carefully before installing. Use sandbox or read-only credentials where possible, store secrets only in a proper secret manager or environment configuration, restrict token scopes, verify every Slack/Airtable/Zapier destination before enabling automated reports, and avoid exposing customer or transaction data unless that sharing is intended.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill encourages connecting live financial systems and sending automated reports to third-party services, but it does not clearly warn users about the sensitivity of transaction data, account credentials, or the risks of exposing financial information in prompts and integrations. In this context, users may provide production keys, customer revenue data, or workspace destinations without understanding the security implications, increasing the chance of data leakage or misuse.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The setup instructions explicitly tell users to configure sensitive secrets such as Stripe live keys, PayPal credentials, Google service account JSON, Slack bot tokens, and Airtable API keys, but they do not include safeguards on secret handling, rotation, scoping, or storage. Because these credentials can provide direct access to payment data, reporting channels, and connected business systems, poor guidance here materially raises the risk of credential exposure and downstream account compromise.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.