api-cost-tracker

Security checks across malware telemetry and agentic risk

Overview

This is a local API cost-reporting skill that handles sensitive billing exports, but the included code does not access credentials or make network calls.

Install only if you are comfortable giving the tool billing or usage export files. Review generated reports before sharing them, since they may reveal spend, model choices, and usage patterns. The advertised environment/API auto-detection appears unsupported by the included script.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding
The skill advertises network-capable behavior via API/environment-based analysis but does not declare permissions or boundaries for that access. In an agent setting, this can lead to unexpected outbound requests or access to sensitive billing data using ambient API keys, which is a security and privacy risk even if the feature is intended.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill states it can read usage data from the environment or APIs and auto-detect providers from API keys, but it provides no warning that sensitive credentials and billing/usage records may be accessed. This increases the chance of silent secret use and exposure of commercially sensitive spending data, especially in shared or automated agent environments.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal