Back to skill

Security audit

Tyche Pro — Full Invoice & Payment Intelligence

Security checks across malware telemetry and agentic risk

Overview

This paid invoice-reporting skill appears purpose-aligned and local-only in the inspected code, but users should handle the external purchase, package install, and generated financial reports carefully.

Install only if you trust the publisher, Ko-fi purchase flow, and the PyPI `rich` dependency. Run it from a private working directory, and do not place the generated `tyche_pro_report_YYYY-MM-DD.md` or `tyche_pro_analytics_YYYY-MM-DD.csv` files in shared, synced, or source-controlled folders unless that is intentional.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Intent-Code Divergence

Medium
Confidence
93% confidence
Finding
The skill makes a strong security claim that 'all data stays on your machine' and 'No transmission, no cloud,' yet it instructs users to install a dependency from pip and repeatedly directs them to external purchase/license URLs. Even if the embedded script itself does not transmit data, these claims are misleading because supply-chain installation and external licensing introduce off-host trust dependencies and potential exposure paths. This is dangerous because users may lower their guard based on the local-only claim and execute the skill in more sensitive environments than they otherwise would.

Vague Triggers

Medium
Confidence
81% confidence
Finding
The manifest describes broad invoicing and finance capabilities but does not define clear invocation boundaries or constraints for when the skill should run. In agentic environments, overly broad descriptions can cause inappropriate auto-selection on financial or document-handling tasks, increasing the chance that sensitive invoice data is processed or files are written unexpectedly. The context makes this more dangerous because the skill handles business and client financial data.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The embedded code writes a markdown report and CSV analytics export containing client names, invoice status, project codes, and payment details, but this side effect is not clearly disclosed in the skill description. That omission can lead users or orchestrating agents to run the skill without realizing it will persist potentially sensitive financial data to disk. In a finance-oriented skill, undisclosed data persistence materially increases privacy and confidentiality risk.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.