Back to skill

Security audit

财务

Security checks across malware telemetry and agentic risk

Overview

This finance skill is not clearly malicious, but it asks for broad execution and file-write capability while its instructions are inconsistent and partly unrelated to finance data lookup.

Review this skill carefully before installing. It appears to be a templated finance helper rather than malware, but only use it if you are comfortable granting broad read, write, and command execution capability to instructions that do not clearly define safe finance-data boundaries. Avoid using it for trading, account actions, private financial files, or credential handling unless the publisher narrows and clarifies the behavior.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Intent-Code Divergence

Medium
Confidence
80% confidence
Finding
The documentation presents conflicting operational boundaries: it says the skill is not for real-time trading execution, yet elsewhere advertises command execution capability. This ambiguity can cause an agent or user to overtrust the skill's scope and permit actions with system-side effects that are unnecessary for a finance lookup skill.

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The file simultaneously describes the skill as MD+execute() and as pure Markdown/natural-language driven, creating uncertainty about whether the agent may execute code or only provide guidance. In security-sensitive agent environments, this kind of ambiguity can bypass user expectations and policy enforcement around tool usage.

Intent-Code Divergence

High
Confidence
97% confidence
Finding
The declared purpose is financial tracking, but the output schema is for a code/security scoring report. Such a mismatch is dangerous because it suggests the skill may be a templated or mislabeled wrapper that can induce agents to process the wrong task type, mishandle data, or activate in inappropriate contexts.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation guidance says to use the skill whenever the user needs finance-related functionality, which is overly broad for a skill that claims execution, file, and API capabilities. Broad triggers increase the chance the agent invokes this skill in unrelated or higher-risk financial scenarios beyond its documented competence.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill advertises file writing, API integration, and command execution without clear user-facing warnings or approval gates for data modification and system impact. In agent settings, this can lead to silent external calls, filesystem changes, or shell execution under the guise of a benign finance skill.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.