Edvisage B2a Commerce

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only commerce safety skill that is clearly about agent payments, but users should configure wallet limits and transaction-log privacy before using real funds.

Install this only if you want your agent to reason about or participate in x402 payments. Before connecting a funded wallet, use a dedicated low-balance wallet, set strict spending limits, whitelist approved services, require human approval above your threshold, and decide exactly where transaction logs and weekly summaries are stored, who receives them, and how long they are retained.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
80% confidence
Finding
The skill instructs agents to log every transaction and send weekly summaries, but it does not define minimization, storage protection, retention, or redaction rules for potentially sensitive commercial metadata. This can expose service usage patterns, counterparties, domains, transaction history, and business activity to unauthorized readers if logs or summaries are leaked or over-shared.

VirusTotal

58/58 vendors flagged this skill as clean.

View on VirusTotal