Back to skill

Security audit

Valuation

Security checks for vulnerabilities and agentic risk

Overview

This skill is marketed as a valuation modeling tool but mainly acts as a persistent local log, search, and export utility for potentially sensitive finance inputs.

Treat this as a local persistent logging tool, not a valuation model builder. Do not enter confidential company forecasts, deal notes, board assumptions, or client data unless you are comfortable storing them in local plaintext logs and possible exports; confirm cleanup and storage controls before use. I did not find network exfiltration or destructive behavior.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a valuation modeling tool, but the documented behavior is primarily a generic persistent logger that stores arbitrary user input, maintains history, supports search, and exports all collected data. This mismatch is dangerous because users may enter sensitive financial assumptions, company data, or deal information expecting analysis functionality, while the skill instead persistently records and exposes that data through local logs and export features without prominent warning.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest and branding claim DCF/comparable-company valuation capabilities, but the documented commands only provide logging, search, status, and export behavior. In a finance context, this can mislead users into supplying confidential valuation data, projections, or board-level assumptions to a tool that does not perform the promised analysis and instead stores the information in retrievable local files.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script does not implement any valuation, DCF, or comparable-analysis functionality despite claiming to do so; instead it collects arbitrary user inputs across many commands and stores them in persistent local logs. That mismatch is dangerous because users may enter sensitive financial assumptions, company data, or deal notes believing they are being processed for valuation, while the skill silently acts as a data collection utility.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The top-level documentation contradicts the stated valuation purpose by describing a tracking and management toolkit for generic operations. While this is primarily a documentation integrity issue, it materially increases security risk by obscuring that user inputs become part of a persistent audit trail and may later be searched or exported.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description does not warn that user-provided valuation data is written to local per-command logs, a unified history log, and export files. Because valuation workflows often involve confidential financial metrics, forecasts, and transaction-sensitive notes, omission of this warning can lead to unintended retention and broader exposure of sensitive information.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script creates a hidden per-user data directory, records command history, and provides search/recent/export functions over that history, which are unrelated to a valuation tool's stated purpose. In this context, these surveillance-style features increase the risk of collecting and exposing sensitive business or financial inputs without a clear operational need.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The help text advertises functional export and status subcommands, but the case statement first routes 'export' and 'status' into generic logging handlers, preventing the documented implementations from being reached. This deceptive interface can mislead users about what the commands do and conceal persistent logging behavior behind expected utility operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The export functionality aggregates all locally stored history into new files on disk, potentially broadening exposure of previously collected sensitive inputs and making accidental disclosure easier. Because this skill is framed as a finance/valuation assistant, exported history may contain highly sensitive commercial information, increasing the harm from silent bulk export.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

User-provided command inputs are written directly to persistent log files in the user's home directory without explicit warning, consent, or data handling guidance. For a valuation skill, those inputs may include confidential company metrics, forecasts, transaction details, or client information, making silent persistence a meaningful privacy and confidentiality risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.