Back to skill

Security audit

Expense Report

Security checks across malware telemetry and agentic risk

Overview

This is a coherent expense-report helper with only minor transparency and trigger-scope caveats.

Before installing, treat it as a helper for expense summaries and reimbursement reports. Avoid giving sensitive receipts unless needed, and ask the agent to return the report inline unless you explicitly want a file written.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger phrases are broad enough to match many ordinary finance-related requests, which can cause the skill to activate outside the user's specific intent to create an expense report. In context, this can lead to misrouting user requests and unintended use of the skill's read/write capabilities, even though the skill itself is not overtly malicious.

Missing User Warnings

Low
Confidence
78% confidence
Finding
The skill declares the write tool but the description does not clearly warn that generated reports may be written to files, which reduces transparency and informed consent. In this business/finance context, silent file creation is lower risk than arbitrary code execution, but it can still expose sensitive expense data or surprise users with unintended persistence.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.