Back to skill

Security audit

Freight Broker — Lane Pricing & Load Decision

Security checks across malware telemetry and agentic risk

Overview

This is a guidance-only freight pricing skill with no executable code or hidden access, though users should keep contract-rate and approval rules in mind.

Installers should treat this as decision-support only: verify market benchmarks and carrier costs, do not use it where a locked contract rate or company approval workflow governs the lane, and have a human owner approve real pricing decisions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The metadata description uses broad natural-language triggers such as 'what should I quote' and 'is this rate any good,' which can match a wide range of ordinary pricing or rate-discussion requests. In an agentic system, this can cause the skill to activate outside its intended scope and influence decisions where a contracted workflow, compliance rule, or another more specific skill should govern.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The primary activation criteria are ambiguous because they list several business scenarios without defining precise boundaries for when the skill should or should not take control. This ambiguity increases the risk of incorrect skill selection, leading the agent to apply pricing-decision logic to situations that may require fixed-rate handling, human approval, or a different decision framework.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.