Ledger Project Expense Entry

Security checks across malware telemetry and agentic risk

Overview

This is a coherent local bookkeeping skill that appends disclosed ledger entries, with manageable risk from terse inputs and lack of a mandatory confirmation step.

Install this only if you want an assistant to append local ledger entries from short expense messages. Review the local add_ledger_entry.py script and check the returned file path and summary after each entry so mistaken records can be corrected.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The invocation description includes broad triggers like sending "项目+支出" directly or asking for "quick记账," which can overlap with ordinary conversation and cause the skill to activate on ambiguous user messages. In a skill that writes persistent ledger entries, unintended activation can lead to unauthorized or incorrect data being appended without sufficient user confirmation.

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
The skill description is written to trigger on Chinese-language patterns and defaults, which can constrain interaction language without explicit user opt-in. This is primarily a safety and usability issue: users operating in another language may misunderstand what will be recorded, increasing the chance of incorrect financial entries or unnoticed assumptions.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal