Back to skill

Security audit

Finance Toolkit Free

Security checks across malware telemetry and agentic risk

Overview

This finance quote skill appears intended for market lookup and local watchlists, but it asks for broad write and exec authority while providing only placeholder instructions and unclear data-flow boundaries.

Review this before installing. The intended finance lookup use is understandable, but install only if you are comfortable granting local file write and shell execution to an artifact that does not include the referenced implementation files. Do not use callback_url with portfolio or watchlist data unless the publisher documents exactly what will be sent and where.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
89% confidence
Finding
The manifest broadens the skill from simple quote retrieval into generic analysis, reporting, statistics, visualization, and export use cases without any concrete implementation boundaries shown in this file. That mismatch can cause an agent to invoke the skill in contexts beyond its verified functionality, increasing the chance of unsafe delegation, misleading outputs, or misuse of attached tools.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The skill is presented as a local market-data lookup tool, but it requests unrestricted exec access without a clear, minimal justification in the documentation. In an agent environment, unnecessary exec rights materially raise the attack surface because broad shell execution could be abused for arbitrary command execution, file access, or network activity unrelated to quote retrieval.

Intent-Code Divergence

Medium
Confidence
83% confidence
Finding
The documentation states watchlist data stays local and is never uploaded, yet the input format includes a callback_url for asynchronous notifications. That contradiction can mislead users and agents about data egress, creating privacy and trust risks if portfolio-related data, logs, or results are sent to external endpoints.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The usage trigger includes very broad categories like data analysis, report generation, statistics, and visualization, which go well beyond a simple quote-tracking utility. Overbroad routing criteria can cause agents to select this skill for unrelated tasks, exposing exec/write capabilities and increasing the chance of inappropriate execution or over-privileged handling.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The capability coverage section enumerates a large set of fragmented keywords that effectively advertise the skill for an ambiguous, expansive range of scenarios. In agent ecosystems, this kind of broad keyword stuffing can distort skill selection and lead to overuse of a tool with read/write/exec permissions in contexts that do not require it.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.