Card Management

Security checks across malware telemetry and agentic risk

Overview

This skill is coherent for card management, but it gives an agent access to payment-card secrets and card-changing actions without enough explicit user-control and masking rules.

Review before installing. Use only with a trusted payment account and verified API host, and require explicit confirmation before creating, revealing, locking, unlocking, or cancelling cards. Do not display, store, or log full card numbers, CVVs, ATM PINs, transaction PINs, bearer tokens, or other payment credentials in chat unless a secure reveal workflow is provided.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly documents a path to retrieve full unmasked card number, CVV, and expiry, but it does not require strong user-facing safeguards such as explicit consent, redaction-by-default, anti-replay checks, or a prohibition on displaying the data back in chat. In an agent context, this is dangerous because PAN/CVV are highly sensitive payment credentials, and an over-permissive or socially engineered request could cause the agent to disclose them directly into conversation logs or other downstream systems.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal