Back to skill

Security audit

Ai Finance

Security checks across malware telemetry and agentic risk

Overview

The skill is a finance-analysis guide, but it describes automated trading and recurring financial tasks while requesting execution/API capability without clear safeguards.

Review carefully before installing. Use this only for advisory analysis unless you separately add explicit human approval for any trading, account-impacting, scheduled, or API-key-backed workflow. Keep API keys least-privileged and avoid enabling unattended execution without clear cancellation and logging.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The skill claims that risky code and external dependencies were removed and that security was enhanced, yet the same document advertises exec capability, API-key usage, dependency installation, and network-backed financial workflows. This mismatch can mislead users and reviewers into trusting a skill that still has meaningful execution and data-exposure risk, increasing the chance of unsafe deployment.

Intent-Code Divergence

Medium
Confidence
88% confidence
Finding
The document presents 'MD: pure SKILL.md, no code execution' as an availability classification while the declared tools include exec and other sections instruct users to run shell commands and install packages. This inconsistency can cause operators to enable the skill under a lower-risk assumption than warranted, weakening review and sandboxing decisions.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The activation guidance says to use the skill whenever the user needs AI-driven financial analysis, which is broad enough to match many ordinary finance-related prompts. Overbroad routing can cause the skill to activate in contexts involving sensitive financial decisions, credentials, or high-impact actions without sufficiently narrow user intent.

Vague Triggers

Medium
Confidence
80% confidence
Finding
The summary language is generic and lacks trigger constraints, making the skill eligible for broad finance-adjacent requests. In a financial context, ambiguous activation increases the chance that the agent will overreach into risky analysis or action-taking workflows that users did not explicitly authorize.

Missing User Warnings

High
Confidence
95% confidence
Finding
The skill describes integration with trading systems to enable automated trading decisions but does not include prominent warnings, human-approval requirements, or account-impact safeguards. In the finance domain this is especially dangerous because mistaken or manipulated outputs can directly cause monetary loss, unauthorized transactions, or regulatory issues.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The documented scenario sets up a recurring daily stock-screening task with automatic execution and result pushing, but it does not warn users about persistent autonomous behavior, scheduling scope, or how to revoke it. Ongoing unattended actions can amplify errors over time and create unwanted monitoring, notification, or downstream decision risk.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.