Claude for Financial Services: why it is not safe to use
We found no hidden code or embedded secrets, but this skill connects to multiple named third-party financial and document systems at runtime.
What we found
Our review did not find hidden instructions, hardcoded secrets, obfuscated code, or scripts aimed at destructive actions. The inspected files openly describe activation and deployment, and the deploy flow expects the `ANTHROPIC_API_KEY` from the environment.
The main concern is data flow. This skill is designed to connect at runtime to multiple remote MCP servers and external services, including Daloopa, Morningstar, S&P Global, FactSet, Moody's, LSEG, PitchBook, Egnyte, and Box. In practice, that means prompts, queries, and related financial or document context may leave the local environment and be sent to those named third parties. We also found that the skill is intended to work with inherently sensitive systems such as wealth-management, research, and document-store workflows.
What to do instead
Use this skill only if you intend to connect those external services and your team understands what data may be shared with them. Before installing, review which connectors are needed, limit access to the minimum required sources, and avoid using it for sensitive financial or document workflows unless those third-party destinations are approved by your organization.
Source: https://github.com/anthropics/financial-services
We report what our security review found at the time we checked, with the goal of keeping people safe. Projects change; if a maintainer has since fixed this, we are glad to recheck it. Email hello@agentpod.com.