Token Budget Advisor

Security checks across malware telemetry and agentic risk

Overview

This skill only changes how the assistant manages answer length and does not request access to files, credentials, commands, or network services.

Installers should expect the skill to sometimes pause and ask for a preferred answer depth, and its token estimates are approximate. If unwanted activations would be disruptive, narrow the trigger wording before use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger conditions are broad enough to match common conversational phrases like 'brief', 'short version', or 'detailed', which can cause the skill to activate when the user did not intend to invoke token-budget controls. This can unexpectedly alter response flow, add extra interaction turns, and interfere with higher-priority task handling, though it does not directly introduce code execution or data exfiltration risk.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The manifest description advertises vague trigger phrases without contextual boundaries, increasing the chance that orchestration or discovery systems will associate the skill with ordinary requests that merely mention concise or detailed answers. This raises the likelihood of unintended activation across many benign prompts, causing workflow disruption and response inconsistency.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal