Back to skill

Security audit

Agentic Invoice Skill

Security checks across malware telemetry and agentic risk

Overview

This skill locally drafts invoice-style PDFs from user-provided billing facts and does not show hidden networking, credential access, payment execution, or persistence.

Install only if you want a local helper for drafting invoice and billing documents. Review invoice numbers, amounts, taxes, payment instructions, contract references, approval status, receipts, credits, refunds, and void notices against your accounting source before sending or relying on generated output.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Description-Behavior Mismatch

Medium
Confidence
86% confidence
Finding
The pro forma invoice template enables generation of a payable-looking billing document before final signature, which is not clearly anchored to verified contract or payment facts. In a billing skill explicitly scoped to verified facts, this creates a mismatch that could be exploited to draft misleading pre-contract payment demands or procurement artifacts that appear more authoritative than the underlying business state warrants.

Description-Behavior Mismatch

Medium
Confidence
81% confidence
Finding
These templates support conditional or status-changing billing documents such as voids/receipts/replacements based largely on placeholders, without an explicit requirement that the underlying accounting state be verified. In a skill meant to operate only from verified contract, SOW, milestone, and payment facts, this could let a user generate documents that falsely assert payment status, void prior invoices, or imply credits/refunds without authoritative backing.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.