Financial Overview

v1.0.0

Get a complete financial overview of the business including balance, recent transactions, outstanding invoices, and upcoming tax obligations. Use when the us...

0· 1.2k·6 current·6 all-time
byStan Kharlap@stanlee000
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
!
Purpose & Capability
The SKILL.md instructs the agent to call finance-specific functions (get_company_details, get_company_balance, search_transactions, list_invoices, get_vat_next_report, get_company_tax_statistics) which align with a 'financial overview' skill. However, the metadata also lists a required mcp 'norman-finance' connector but the skill declares no environment variables, credentials, or config paths. A connector that accesses company financial data would typically require explicit credentials or configuration; the omission is a mismatch.
Instruction Scope
The instructions are narrowly scoped to specific finance API/function calls and to presenting results in EUR. They do not instruct reading local files, environment variables, or unrelated system paths, nor do they direct data to arbitrary external endpoints beyond the implied 'norman-finance' connector.
Install Mechanism
This is an instruction-only skill with no install spec and no code files, so nothing is written to disk by the skill itself. That reduces install-time risk.
!
Credentials
The skill will expose and aggregate sensitive financial information but declares no required environment variables, primary credential, or config paths. The embedded metadata's 'requires: mcp: norman-finance' implies an external integration that almost certainly needs credentials or access tokens; not declaring them is disproportionate and leaves unclear how authentication/authorization is handled.
Persistence & Privilege
The skill does not request always:true and does not indicate changes to other skills or system-wide settings. It uses normal autonomous-invocation defaults (disable-model-invocation: false), which is expected for skills and not flagged on its own.
What to consider before installing
Before installing, verify the norman-finance connector: ask the publisher what credentials/tokens the connector requires and exactly where data is sent and stored. Confirm the MCP's domain and privacy/security policy (the SKILL.md references https://norman.finance but the registry lists no homepage/source). Do not grant broad account or admin credentials; prefer least-privilege API keys scoped to read-only financial data. If possible, test the skill in a non-production environment and require the author to explicitly declare needed environment variables and a data-retention/privacy statement. If you cannot verify the connector owner or where financial data is transmitted/stored, treat installation as risky and avoid providing real company credentials.

Like a lobster shell, security has layers — review code before you run it.

bookkeepingvk97dgsepagty6401pb17f6kw8181e82wdashboardvk97dgsepagty6401pb17f6kw8181e82wfinancevk97dgsepagty6401pb17f6kw8181e82wlatestvk97dgsepagty6401pb17f6kw8181e82wmcpvk97dgsepagty6401pb17f6kw8181e82w

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Runtime requirements

📊 Clawdis

Comments