Back to skill

Security audit

Ai Finance Free

Security checks across malware telemetry and agentic risk

Overview

The skill is not clearly malicious, but it asks for executable finance workflows, API keys, exports, and recurring monitoring without clear limits or user controls.

Review this carefully before installing. Only use it with non-sensitive financial data unless you are comfortable granting exec access and configuring finance API keys. Confirm any export, scheduled task, monitoring alert, or portfolio-related request before letting the agent act, and check where generated files or history will be stored.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The skill claims that risky code and external dependencies were removed, yet the same document requires external financial APIs, environment-variable API keys, executable tooling, and network data access. This mismatch can mislead users and agents into granting trust or permissions they would not otherwise allow, increasing the chance of unsafe execution or secret exposure.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The document presents itself partly as a pure SKILL.md experience while also instructing Python setup, shell environment export, and MD+EXEC operation. This inconsistency obscures the real execution boundary and may cause an agent or user to enable exec-capable workflows unexpectedly.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The activation guidance is overly broad, effectively suggesting use whenever finance-related functionality is requested. Ambiguous invocation scope can cause the skill to activate in situations involving sensitive financial data, trading decisions, or system actions without sufficiently specific user intent.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill advertises exporting results and automation features without clearly warning about where files are written, what data may be persisted, or what side effects may occur. In a finance context, exports can contain sensitive portfolio, market, or API-derived data, making silent persistence and downstream handling risky.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The document describes scheduled recurring execution and continuous monitoring without warning that it will repeatedly access data sources and keep performing actions over time. This can create unintended ongoing network activity, excessive API usage, recurring charges, or repeated handling of sensitive financial data.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.