Back to skill

Security audit

Group Buy Helper

Security checks across malware telemetry and agentic risk

Overview

This is a text-only shopping helper for group-buy and bargain advice, with no code, credential use, network access, or persistence found.

Before installing, expect this skill to provide estimates and persuasive text only. Treat its success probabilities as informal advice, not platform-official data, and review any generated share message yourself before sending it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The activation guidance is broad enough that a host agent could invoke this skill for loosely related shopping or social-sharing requests without a clear boundary check. That can cause misrouting, irrelevant persuasive-message generation, or inappropriate use in contexts the user did not intend, though it does not by itself introduce direct code execution or data exfiltration risk.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The sample commands are short and generic, which increases the chance that a planner or router will match this skill on ambiguous user input. In practice this can lead to accidental activation, lower-quality responses, and generation of recruitment copy in situations where the user may have intended a different shopping or messaging task.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.