SCF Quick Compare

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed QuickBooks cash-flow reporting helper, but users should handle its reports and cache as sensitive financial data.

Install only in a workspace trusted for client financial data. Verify the referenced local Python script before use, limit QuickBooks access to the intended company, and delete or protect the generated Excel files and .cache/scf-quick-compare cache when they are no longer needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
82% confidence
Finding
The skill explicitly accesses QuickBooks Online financial data and stores a local cache of statement data, but the description does not clearly warn users about that behavior. This can lead users to run the skill without understanding that potentially sensitive financial information will be retrieved from QBO and persisted locally in `.cache/scf-quick-compare/{slug}.json`, increasing the risk of unintended data exposure on shared or insufficiently secured workstations.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal