Accounting Workflows

Security checks across malware telemetry and agentic risk

Overview

This skill is a local accounting workflow guide with no hidden network access or bundled executable code; review optional email/export companion setup before using it.

Install this only with an OPENCLAW_DATA_DIR you control, and approve any jq package installation yourself. Treat email monitoring, OCR, AADE/EFKA filing, and QuickBooks/Xero export as separate higher-privilege companion capabilities that should be scoped and reviewed before enabling.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The email-monitoring eval asks the agent to "set up my daily email monitoring system" and automatically process financial documents without defining clear scope, authorization checks, mailbox boundaries, or approval gates. In an agent-skill context, this can normalize over-broad autonomous access to sensitive communications and attachments, increasing the risk of unauthorized data access, over-collection, and unsafe automation if implemented literally.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal