Personal Finance

Security checks across malware telemetry and agentic risk

Overview

This is a local personal-finance CSV helper with disclosed, purpose-aligned behavior and no evidence of hidden network access, credential use, persistence, or destructive actions.

Install only if you are comfortable giving the skill access to the specific financial CSVs you choose. Keep real exports local, review any categorized output before sharing it, and avoid reusing the sample account-number style in public examples.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Low
Confidence
96% confidence
Finding
The sample CSV includes an unmasked account number-like identifier ("CHK-123456789") for every transaction record. Even in sample data, exposing financial identifiers normalizes unsafe handling of sensitive information and can leak private details if the file is real, reused, or copied into logs, demos, or downstream systems.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal