Back to skill

Security audit

CFO Global Super Expert System

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed CFO assistant router that loads finance-related sub-skills and does not show hidden data theft, destructive behavior, or persistence.

Install this if you want a broad CFO workflow that can consult other installed finance-related skills. Review the underlying sub-skills before relying on outputs for investment, legal, audit, or compliance decisions, and treat its recommendations as research rather than professional advice.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding
The skill claims to be a CFO advisory system, but it also instructs the agent to enumerate installed sub-skills, search a skill registry, inspect metadata, and read arbitrary SKILL.md files from a shared skills directory. That expands behavior into capability discovery and filesystem inspection not clearly disclosed in the description, which can expose internal system structure and create unexpected data access paths.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The routing table uses broad, common keywords like 'market', 'industry', 'CPA', 'audit', 'CEO', and 'strategy', which can cause the skill to activate for loosely related requests and then read additional sub-skill files or invoke tooling unexpectedly. In an agent environment, over-broad dispatch increases the chance of unintended tool use, privacy leakage, or policy bypass through ambiguous prompts.

Static analysis

No suspicious patterns detected.