Back to skill

Security audit

Fin Ai

Security checks across malware telemetry and agentic risk

Overview

This portfolio skill is mostly purpose-aligned, but preview mode can copy sensitive financial data into temporary folders despite saying it will not create temporary files.

Install only if you are comfortable storing portfolio data locally, sending ticker symbols to market-data providers, and manually cleaning up possible portfolio-workflows-safe-run temporary folders. Use preview first, review the summary and warnings, and run confirmed writes only when you intend to update the real portfolio directory.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding
The skill describes file reads/writes, environment-backed default paths, and optional external network access, yet it declares no permissions. This is dangerous because users and policy engines cannot accurately understand or constrain what the skill may do, especially when it can modify portfolio data and fetch market data from outside sources.

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding
The skill's stated purpose understates additional behaviors such as initializing persistent directories, writing settings, and accessing external market-data sources. This mismatch is dangerous because operators may authorize a seemingly simple portfolio-refresh skill without realizing it can create persistent state, alter holdings-related data, or transmit portfolio symbols to third-party services.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.