Complex Mathematics Engine

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed remote math-tool wrapper; its main caution is that broad trigger words could cause more content than intended to be sent to AgentPMT.

Install only if you intend to use AgentPMT for math calculations and are comfortable sending the expression text to AgentPMT and potentially spending credits. Avoid placing secrets, wallet data, or unrelated private content in expressions, and consider narrowing activation behavior locally if your agent auto-invokes skills on generic words.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill advertises activation keywords including generic terms like "calculate" and "expression," which are common in ordinary user requests and unrelated contexts. This can cause unintended tool invocation and unnecessary transmission of user-supplied content to a remote service, expanding the chance of privacy leaks or unsafe autonomous behavior.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal