Back to skill

Security audit

Financial Admin

Security checks for vulnerabilities and agentic risk

Overview

This skill provides read-only fund administration workflows and does not include executable code, hidden installation behavior, or automatic financial changes.

Install only in environments where the agent is allowed to read relevant fund accounting data. Keep ledger posting, statement editing, and resolver actions behind human approval or separate controlled tools, because this skill is designed to draft and diagnose rather than execute financial changes.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.