Back to skill

Security audit

Financial Close Checklist

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only financial close checklist, with expected but high-impact accounting steps that should stay under human approval.

Use this as a close planning and tracking aid. Before posting journal entries, scheduling payments, locking a period, exporting reports, or sending financial packages, verify the company, period, amounts, recipient list, and reviewer approval in the accounting system.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill instructs users to lock the accounting period and distribute financial packages, both of which are state-changing or sensitive operations, but it does not explicitly warn that these actions can prevent further edits or expose financial data to stakeholders. In a finance workflow, executing these steps prematurely or automatically could disrupt close corrections, create operational friction, or leak incomplete financials.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The integration section explicitly mentions pulling actuals from QuickBooks and posting accruals and journal entries programmatically, but provides no warning that these are write actions affecting the accounting ledger. Because accounting records are highly sensitive, unreviewed or unintended automated postings could materially alter financial statements, create audit issues, and require cleanup entries.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.