Back to skill

Security audit

AI Cost Estimator

Security checks across malware telemetry and agentic risk

Overview

This is a non-executable AI cost guide with visible vendor promotion, not a technical security threat.

Safe to install as a reference skill, but treat the pricing, ROI examples, and AfrexAI comparisons as marketing material. Verify current prices and compare independent alternatives before making budget or vendor decisions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill is presented as a neutral cost-estimation tool, but the latter portion of the file pivots into product promotion for a specific vendor, including pricing comparisons, favorable framing, and direct consultation/sales links. This is dangerous because an agent or user may treat the skill as objective decision support when it is actually biased marketing content, leading to conflicted recommendations and trust erosion.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal