Back to skill

Security audit

MS Financial Model

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Excel financial-model generator, but it can write untrusted input into spreadsheets as executable formulas and includes a misleading margin chart calculation.

Install only if you control and trust the input data, or sanitize text fields before generating and sharing workbooks. Treat generated margin charts as potentially approximate and review formulas before using the workbook for investment or valuation decisions.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/ms_financial_model.py:474
Finding

Excel Formula Injection Through Unsanitized Model Text

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill description is broadly scoped to many common finance requests such as financial modeling, DCF, SOTP, sensitivity, PE band, and comparables analysis. Overly broad invocation criteria can cause the agent to trigger this skill in situations where it is unnecessary or where user data should not be routed into complex spreadsheet-generation workflows, increasing the attack surface for prompt injection, unintended file generation, or mishandling of sensitive financial inputs.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The code sets Chinese as the default language in both helper logic and the CLI (language: str = "zh", default="zh"), which forces a specific locale unless the user explicitly overrides it. This is a natural-language locale policy concern because the default behavior does not first offer or infer a language choice from the user.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The chart helper claims to present Gross Margin and Net Margin, but when those rows do not exist it silently fabricates proxy metrics from EBIT/Revenue and NOPAT/Revenue. In a financial modeling skill, this can mislead users into trusting materially incorrect outputs, which is dangerous because the generated workbook is meant to support valuation and investment analysis.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The usage examples hard-code language="zh" and --lang zh, which presents a specific language choice as the default invocation. Under the policy, forcing a language/locale without explicit user opt-in is a natural-language policy concern, and the README does not offer a neutral default or call out this as an optional example choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.