Back to skill

Security audit

quota-management

Security checks across malware telemetry and agentic risk

Overview

This skill is a documentation-only quota-management guide with broad activation phrases but no hidden execution, credential access, or install-time behavior.

This appears safe to install as a guidance skill. Users should be aware it may activate on broad quota or threshold discussions, and any real tracker built from these examples should make storage, queuing, and service fallback behavior explicit.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrase "quota" is extremely broad and likely to appear in ordinary user conversations, increasing the chance that this skill is invoked outside its intended context. Over-broad activation can cause unintended routing, context pollution, or execution of quota-management guidance when the user did not ask for it, which is a genuine security and reliability concern in agent systems.

Vague Triggers

Medium
Confidence
92% confidence
Finding
Several triggers, including terms like "rate-limiting", "thresholds", and "cost-tracking", are broad enough to match general discussion rather than a clear request to invoke this specific skill. In an agent environment, ambiguous triggers can lead to accidental skill activation, unnecessary dependency loading, or the application of quota-handling behavior in irrelevant contexts.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.