Back to skill

Security audit

规划虾 Asset Planner

Security checks across malware telemetry and agentic risk

Overview

This prompt-only finance skill is not malware, but it asks for sensitive financial screenshots, suggests specific trades, and tells the agent to remember financial history without clear privacy limits.

Install only if you are comfortable sharing sensitive portfolio information with the agent. Redact names, account numbers, QR codes, transaction details, and unrelated balances before uploading screenshots, and treat any named fund or buy amount as informational planning output to verify independently before acting.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The knowledge base explicitly says the product should avoid investment recommendations, yet elsewhere instructs the AI to output concrete buy commands for named funds and ETFs. This contradiction can cause the skill to act as an unlicensed or undisclosed financial advisor, increasing legal/compliance risk and potentially driving harmful user actions under the guise of neutral tooling.

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The file markets the product as a neutral third-party calculator and information organizer, but many sections provide prescriptive portfolio construction advice and named product allocations. That mismatch is dangerous because it can mislead users and reviewers about the system's actual behavior, weakening informed consent and creating compliance, trust, and consumer-protection risks.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly asks users to submit asset allocation screenshots containing highly sensitive financial information, but it does not provide an upfront privacy warning, minimization guidance, or advice to redact account identifiers before upload. In a finance-oriented skill, this increases the chance that users will disclose balances, account numbers, names, or platform details without understanding the privacy implications.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill proposes collecting screenshots from banking, brokerage, and payment apps and running OCR over them, which can expose highly sensitive financial data such as balances, account identifiers, holdings, and transaction details. Without clear warnings, consent language, minimization rules, retention limits, and secure handling requirements, users may unknowingly disclose data that could be abused or leaked.

Ssd 3

Medium
Confidence
96% confidence
Finding
The instruction to 'remember everything' about a user's historical allocations, risk preferences, and position changes effectively directs indefinite retention of highly sensitive financial profiling data. In a personal finance skill, such long-term storage materially raises privacy and misuse risk, especially if retention limits, consent, and deletion controls are absent.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.