Budget Vs Actual

ReviewAudited by ClawScan on May 10, 2026.

Overview

The skill is an instruction-only finance workflow, but the package appears to include a test report with a named real client’s financial details.

Review the included DOGFOOD test file before installing or sharing this skill. The core SKILL.md is a coherent finance analysis guide, but the package should be cleaned of real or client-identifying financial data and replaced with synthetic examples.

Findings (2)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

A user or organization could unintentionally receive, index, or reuse another client’s confidential financial details when installing or using the skill package.

Why it was flagged

The distributed artifact appears to include named client financial information from a real engagement. This is not needed for the skill’s operation and could expose sensitive business data to anyone installing or reviewing the skill.

Skill content
Applied the budget-vs-actual skill to a real client engagement: SB Paulson LLC, a salon/spa business generating ~$210K/month in revenue. Used actual P&L data for Jan–Feb 2026
Recommendation

Remove the dogfood report or replace it with fully synthetic, anonymized sample data before distribution.

What this means

The agent may process confidential company budgets, accounting exports, and management reporting data.

Why it was flagged

The skill expects users to provide internal financial documents and accounting exports. That is purpose-aligned, but these inputs are sensitive and should be handled carefully.

Skill content
Budget/forecast file (CSV, Sheets, or typed data) ... Actuals file or QBO export ... Chart of Accounts mapping
Recommendation

Use only intended files, avoid unnecessary client or employee details, and confirm where generated reports will be stored or shared.