Back to skill

Security audit

Buying

Security checks across malware telemetry and agentic risk

Overview

This is a shopping comparison skill that gives purchase recommendations from public marketplace information and does not include code, credential access, persistence, or payment authority.

Use this as decision support, not as authority to spend money. Verify current prices, seller identity, return terms, and coupons yourself before checkout, and do not allow account login, private order access, messages to sellers, or payment unless you separately and explicitly intend that.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The default prompt authorizes broad comparison across multiple marketplaces and 'similar marketplaces' without clear scope boundaries, eligibility rules, or safety constraints. In an agent setting, this can lead to overbroad invocation, unintended shopping guidance, unsupported site handling, or unsafe assumptions about seller trust and pricing that increase the chance of misleading recommendations.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.