Cost

Security checks across malware telemetry and agentic risk

Overview

This is a text-only business cost-management advisor with no executable code or account access, though users may share sensitive financial details while using it.

Reasonable to install if you want help analyzing business costs, margins, pricing, and vendor spend. Be aware it may trigger on general finance terms, and redact unnecessary sensitive financial details before pasting data into an agent.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger list includes broad, common business terms such as "cost," "pricing," and "overhead," which can cause the skill to activate in many ordinary conversations where the user did not intend to invoke this specific skill. This increases the chance of unintended routing, context hijacking, or inappropriate responses from the agent, especially in environments with multiple overlapping skills.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal