Back to skill

Security audit

Privacy virtual credit cards

Security checks across malware telemetry and agentic risk

Overview

This is a legitimate Privacy.com CLI helper, but it can access and change financial card data and lacks enough built-in confirmation for permanent card actions.

Install only if you intend to let an agent manage Privacy.com virtual cards. Require explicit confirmation before creating, updating, pausing, unpausing, revealing PAN data, or permanently closing a card, and verify the exact card token or memo before any command runs. Protect PRIVACY_API_KEY and approve any global npm installation yourself.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger description is broad enough that the skill may activate on generic card-management requests without clearly establishing that the user intends to operate on Privacy.com virtual cards via this tool. In a financial-management context, unintended invocation can lead to sensitive account actions or data access being routed through the skill when a narrower match or clarification should have been required.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill exposes a permanent card-closing command but does not require an explicit confirmation step or warning about irreversibility. In a payments context, accidental or mis-triggered execution could permanently disable a user's virtual card, disrupting transactions and causing financial or operational harm.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.