Back to skill

Security audit

Invoice Agent

Security checks across malware telemetry and agentic risk

Overview

This is a local invoice-management skill that drafts invoices and reminder text, with no evidence of hidden sending, network access, or credential use.

Install this only if you want a local invoice and reminder drafting workflow. Treat generated reminders, especially final notices, as drafts for manual review, and keep the ~/.invoice-agent data directory protected because it can contain client names, emails, addresses, invoice amounts, and payment status.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
76% confidence
Finding
The skill advertises generating and sending payment reminders with escalating tone, including final notices with legal-warning language, but the documentation does not clearly warn users about the business and reputational consequences of contacting clients. In an agent context, ambiguous 'send reminders' behavior can lead to unintended outbound communications or coercive/escalatory messages being generated or dispatched without adequate user review.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.