Back to skill

Security audit

Gridman古立特

Security checks across malware telemetry and agentic risk

Overview

This is a finance, tax, audit, and investment-banking assistant skill with broad but disclosed local-tool and memory workflows, and I did not find hidden, deceptive, exfiltrating, or destructive behavior.

Before installing, assume this skill may read and generate sensitive finance files when you ask it to perform audit, tax, invoice, or spreadsheet work. Configure gridman-mind only in a location you are comfortable using for project records, keep credentials only in the separate tools secrets area, and review any external upload or file-write confirmation carefully.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (10)

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
The file explicitly instructs the skill to automatically append per-project audit restriction records into 'mind' memory across conversations. That creates persistent state and project-level data retention behavior inside a knowledge document, which can cause unnecessary storage of sensitive audit facts, client information, and evolving risk assessments beyond the user's immediate request. In an audit/tax skill context, those retained records may include confidential financial issues and opinion-impact analysis, increasing privacy, confidentiality, and cross-session data handling risk.

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The document explicitly promises to exclude unofficial tax-burden warning thresholds and fixed heuristic ratios, but later reintroduces exactly those values in section 7.6 with operational guidance such as treating materially low tax burden as a self-check trigger. In a compliance-focused skill, this contradiction can mislead users into relying on unofficial, potentially inaccurate thresholds as if they were sanctioned guidance, creating legal/compliance risk and undermining trust in the rest of the document.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger list includes generic phrases such as "Hyper Agent", "超级特工", and "SSSS", which can appear in unrelated conversations and cause unintended activation. In a skill that can read memory, inspect files, and invoke host tools or CLI, accidental invocation increases the chance of unnecessary access to sensitive context or execution-capable workflows.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The description says the skill triggers on broadly defined finance, audit, tax, and investment-banking questions, effectively making it a default handler for a very large class of user requests. Because the skill is designed to route into external capabilities, memory access, and local/host tooling, overbroad activation expands the attack surface and raises the risk of unneeded privileged behavior in contexts where the user did not explicitly ask for this skill.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The routing rules activate on very broad phrases such as asking how to think, train, or improve questioning, which are common across many unrelated domains. This can cause unintended skill invocation, expanding the skill’s influence beyond finance/tax contexts and increasing the chance that users receive domain-specific framing or instructions when they did not intend to use this skill.

Missing User Warnings

Medium
Confidence
83% confidence
Finding
The documented batch workflow instructs scanning directories, OCRing invoices, extracting sensitive financial data, classifying files, and merging outputs without any privacy, minimization, consent, or retention guidance. In the context of a skill with host execution ability, this can lead to over-collection and local processing of tax IDs, names, account details, and travel data from unrelated files, increasing the risk of unauthorized access, aggregation, or persistence of sensitive information.

Vague Triggers

Medium
Confidence
83% confidence
Finding
该工作流的触发条件覆盖“汇总审计调整、形成审计结论、完成阶段复核”等广泛表述,且技能级触发词本身也较宽,容易在普通审计咨询或讨论场景中被误加载。一旦误触发,代理可能在缺乏完整输入、授权或上下文确认的情况下进入高风险的审计调整/审定流程,导致错误写入底稿、生成不当结论建议或污染项目记忆。

Vague Triggers

Medium
Confidence
86% confidence
Finding
The activation conditions are broad enough to match ordinary audit-related requests, which can cause the workflow to trigger when the user did not explicitly intend to invoke this high-capability audit orchestration flow. In this skill, that increases the chance of unnecessary access to spreadsheets, evidence indexing, and memory-writing behaviors, which can expose sensitive financial context or lead to overbroad actions.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger condition is broad and semantic rather than tightly scoped to explicit commands, so this workflow could be loaded during ordinary audit discussions that merely mention internal control topics. In a high-risk skill with write-capable spreadsheet/evidence operations and optional script execution, unintended activation can cause over-collection of sensitive data, unnecessary workflow execution, or the agent taking procedural actions the user did not clearly request.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger conditions are broad and include generic finance/audit phrases, which can cause the skill to activate outside the user's actual intent. In a high-trust professional workflow, misactivation can lead to inappropriate handling of sensitive financial data, generation of audit-style outputs without sufficient context, or confusion about the scope and authority of the skill.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.