Back to skill

Security audit

Report Viz Free

Security checks across malware telemetry and agentic risk

Overview

This financial report visualization skill is not overtly malicious, but it asks for broad read/exec capability and external financial-data/API-key use without tight runtime boundaries or clear user consent controls.

Review this before installing if you handle private or proprietary financial data. Use it only for intended financial report visualization tasks, avoid giving it broad filesystem access, configure API keys with minimal permissions, and require explicit confirmation before any command execution, file export, or external API call.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The document claims it removed external repository references and sensitive-information leakage paths, yet still instructs users to configure API keys and use external financial data APIs. This mismatch can mislead users and reviewers about actual data-flow and secret-handling risks, increasing the chance that sensitive data is transmitted externally without informed consent.

Description-Behavior Mismatch

Medium
Confidence
83% confidence
Finding
The skill is presented as a free core visualization/reporting tool, but the body advertises real-time market data, prediction, WebSocket updates, and broader analytics features. This capability sprawl can cause the agent or user to overtrust the skill, invoke it in contexts beyond its safe design boundary, and expose data to unnecessary processing, network access, or command execution paths.

Vague Triggers

Medium
Confidence
81% confidence
Finding
The activation wording is extremely broad, covering generic data analysis, reporting, and visualization requests. In an agent environment with read and exec tools, broad triggers can cause inappropriate invocation on unrelated user content, expanding access to sensitive files or causing unnecessary command execution.

Vague Triggers

Low
Confidence
74% confidence
Finding
The markdown lists capabilities but does not clearly define boundaries or non-goals, making the skill easy to over-apply. While this is primarily a policy and safety-specification weakness, it becomes more dangerous here because the skill advertises exec, file handling, and external integrations.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill mentions API calls, command execution, file output, and environment-variable API keys, but does not provide a clear user-facing warning that these actions may transmit data externally or affect the local system. This weakens informed consent and can lead to unexpected exposure of proprietary financial data, filesystem changes, or secret misuse.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.