Back to skill

Security audit

Earnings Quality Reviewer

Security checks for vulnerabilities and agentic risk

Overview

This is a prompt-only finance review skill that analyzes user-supplied financial statements without tools, code execution, network access, or persistence.

Install this if you want an agent to review earnings quality from financial statements you provide. Because it may be invoked automatically in finance-related conversations, confirm the input data is complete and current, and treat the output as analytical support rather than investment advice.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill enables implicit invocation but does not define clear trigger boundaries, exclusion conditions, or narrow activation criteria. This can cause the agent to invoke the skill in contexts where the user did not explicitly request earnings-quality analysis, potentially leading to unintended processing, misleading outputs, or workflow manipulation if an attacker crafts prompts to trigger it indirectly.

Static analysis

No suspicious patterns detected.