Cost Estimation Resource

Security checks across malware telemetry and agentic risk

Overview

This is a coherent construction cost estimation skill with disclosed filesystem access for spreadsheet-style inputs and Excel exports.

Install only if you are comfortable granting file access for project cost data and exported spreadsheets. Use explicit, trusted input files and output paths, avoid exporting over important files, and review generated estimates before relying on them for bids or budgets.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
80% confidence
Finding
The markdown documents writing an Excel file to an arbitrary output_path without warning the operator that this action performs filesystem writes. In agent contexts, undisclosed file creation or overwrite can lead to unintended modification of local files, especially if the path is influenced by user or tool input.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal