Receivable Aging Analyzer

Security checks across malware telemetry and agentic risk

Overview

This skill is a descriptive receivables-analysis helper that does not access accounts, call external services, or perform transactions.

This appears safe to install for advisory accounts-receivable templates, but users should be aware it may activate for broader finance prompts than intended. Treat its output as informational, verify collection or legal steps with qualified professionals, and avoid entering sensitive financial details unless necessary.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger section is materially overbroad for a skill named and described as a receivable aging analyzer. It invites activation for unrelated finance topics such as budgeting, tax deductions, pricing, and general financial health, which can cause the agent to apply the wrong skill in contexts it was not designed or safety-reviewed for, increasing the chance of misleading or inappropriate guidance.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger keywords include very generic terms such as "receivable," "aging," and "analyzer," which can cause the skill to activate in unrelated contexts. This increases the chance of unintended invocation, confusing routing behavior, and accidental exposure of finance-oriented outputs in conversations that did not explicitly request this skill.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal