finance-exp-distill

Security checks across malware telemetry and agentic risk

Overview

This is a text-only financial-industry knowledge skill with no executable code or hidden data access, though users should treat its financial content as general guidance rather than advice.

Install this if you want a Chinese-language reference for financial-industry methods and best practices. Because it discusses finance, risk, compliance, and wealth management, users should verify current regulations and treat outputs as general educational material, not personalized investment, legal, or compliance advice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation description is broad enough to trigger on many ordinary finance-related conversations, which can cause the skill to activate without clear user intent. In a finance context, unintended activation can steer responses toward preloaded domain guidance, reducing user control and increasing the chance of inappropriate or overconfident financial guidance being surfaced.

Natural-Language Policy Violations

Medium
Confidence
82% confidence
Finding
Forcing Chinese-language output without offering a language choice can override user preference and degrade comprehension, especially in sensitive financial contexts where misunderstanding terminology matters. This is not directly code-execution dangerous, but it can lead to usability and interpretation failures that affect the quality and safety of advice.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal