Back to skill

Security audit

Pricing

Security checks across malware telemetry and agentic risk

Overview

This skill provides pricing strategy guidance and does not show hidden execution, data exfiltration, persistence, or destructive behavior.

Before installing, be aware that the skill may read local product marketing notes to tailor pricing advice. Its recommendations can affect business revenue decisions, so treat outputs as strategic guidance to review rather than automatic actions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The eval explicitly expects the skill to trigger on vague casual phrasing like 'how do we figure out what people will actually pay?' without defining boundaries that distinguish pricing strategy from adjacent domains such as market research, product strategy, sales, or CRO. In an agent-routing context, ambiguous activation criteria can cause overbroad invocation, misrouting user requests, and unintended application of pricing guidance where another skill or safety review should handle the request.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.