Cash Flow Forecast

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed QuickBooks cash-flow forecasting helper, but users should treat its outputs and cache as sensitive financial records.

Install only if you trust the local forecasting script and are authorized to access the selected client's QBO records and SOP files. Prefer sandbox or least-privilege/read-only QBO access first, verify the company slug before running, and remember that generated Excel files plus the CDC cache may contain sensitive cash, runway, and burn-rate information.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill explicitly states it pulls live QBO financial data and reads client SOP files, but it does not require any explicit authorization check, consent prompt, or warning that sensitive financial data and internal client documentation will be accessed. In an agent setting, that increases the risk of over-collection or unintended disclosure of confidential business information if the skill is triggered too casually or for the wrong client context.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal