Back to skill

Security audit

Financial Wealth Management

Security checks for vulnerabilities and agentic risk

Overview

This financial-planning skill appears purpose-aligned, with the main caveat that some broad trigger phrases could start sensitive workflows too easily.

Install only if you want an assistant to help with financial-advisory review and planning workflows. Use explicit prompts, confirm the client or household scope before sharing data, and avoid giving it access to more financial records than needed for the task.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The client-review skill declares several broad natural-language triggers such as "quarterly review," "prep for [client name]," and "client meeting," which can overlap with ordinary financial-advisory conversation. In an agentic environment, this can cause unintended skill invocation and accidental access or summarization of sensitive client portfolio data without sufficiently explicit user intent.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The financial-plan skill includes highly general triggers like "financial plan," "retirement plan," and especially "can I retire," which are common conversational phrases. This increases the chance that routine discussion will automatically launch a planning workflow that gathers extensive personal and financial data, creating privacy and consent risks.

Static analysis

No suspicious patterns detected.