Back to skill

Security audit

Accounting Finance

Security checks across malware telemetry and agentic risk

Overview

The skill is mainly a finance-analysis guide, but it combines command execution and market-data credentials with broad activation wording and mismatched template content, so users should review it carefully before installing.

Install only if you intend to use it for finance-analysis workflows and are comfortable with an agent running local Python commands, creating reports/cache files, and using market-data API credentials. Keep API keys in environment variables or a secret manager where possible, review any generated command before execution, and avoid invoking the skill for generic automation tasks outside finance.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (4)

Intent-Code Divergence

Medium
Confidence
93% confidence
Finding
The documented output schema appears to describe a generic code-review/scoring workflow rather than finance analysis results, creating a semantic mismatch between what users request and what the skill claims to return. This can cause downstream agents or automation to mis-handle outputs, trust incorrect fields, or route sensitive financial data into the wrong processing path.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The activation text is extremely broad, including generic efficiency, automation, batch processing, and workflow optimization language, so an agent may invoke this skill for many unrelated tasks. In a skill with exec capability, over-broad triggering increases the chance of unintended command execution, misuse of credentials, or processing of inappropriate data without clear user intent.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill declares exec capability and later shows Python batch commands and report/output generation, but the early description does not clearly warn users that commands may be executed and files may be created or modified. This reduces informed consent and can lead to unexpected local actions, especially in agent environments that automatically honor tool-enabled skills.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill instructs users to configure external market-data API keys and references local config storage, but it does not provide a clear privacy/security warning about credential handling, data transmission, provider-side logging, or least-privilege practices. Users may assume data remains local when the workflow may send identifiers, prompts, or financial content to third-party services.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.