Earnings Quality Reviewer

Security checks across malware telemetry and agentic risk

Overview

This skill only analyzes financial statement data the user provides and has no code or network tools; its main caveat is that it can be auto-invoked in finance conversations.

Install this if you want finance-related conversations to be eligible for automatic earnings-quality review. Treat the output as analytical support rather than investment advice, and provide only financial statement data and notes you are comfortable sharing with the agent environment.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
Implicit invocation is enabled, but the skill definition does not provide any trigger boundaries, exclusion conditions, or scope constraints. This can cause the agent to invoke the skill in ambiguous contexts, potentially producing unsupported financial judgments or over-trusting incomplete user-supplied data, which is risky in a finance-adjacent workflow.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal