Price for Agent

Security checks across malware telemetry and agentic risk

Overview

This skill is a simple price-lookup helper that only documents calls to a declared market-data API, with a privacy caveat for query text sent to that service.

Safe to install for market price lookups. Keep the generated API key private, and do not include portfolio holdings, trading plans, account details, or other sensitive personal information in natural-language queries sent to the price API.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill instructs agents to send natural-language queries and an agent identifier to a third-party service, but provides no user-facing disclosure or minimization guidance. If users include sensitive financial context or identifiers in their queries, that data may be transmitted externally without informed consent, creating privacy and compliance risk.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal