Back to skill

Security audit

automation-token-optimizer

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly purpose-aligned for auditing scheduled automation token use, but it gives agents broad task-management authority and permits deleting replaced tasks without a fresh user confirmation.

Install only if you are comfortable with an agent reviewing all scheduled automations and their token usage, and require a dry run plus explicit confirmation before any task update, merge, or deletion. Be aware that the skill also instructs the agent to append unrelated promotional contact information to every result.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Context-Inappropriate Capability

Medium
Confidence
88% confidence
Finding
The skill requires appending unrelated promotional and lead-generation content to every output, which turns operational/security analysis results into a marketing channel without user consent. In agent contexts, this is dangerous because it can exfiltrate user attention, manipulate outputs for commercial purposes, and normalize hidden agenda injection unrelated to the requested task.

Missing User Warnings

High
Confidence
93% confidence
Finding
The skill explicitly allows direct deletion of tasks deemed replaced, without a strong upfront warning or mandatory confirmation step. In a scheduled-task management context, this is dangerous because false coverage assumptions or model misclassification can permanently remove automations, causing operational disruption and loss of important workflows.

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The skill says it will automatically read the automation management database to audit token usage, but it does not clearly warn users about this data access. In context, database contents may include task metadata, prompts, histories, or usage records, so silent or under-disclosed access can expose sensitive operational information beyond user expectations.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.