B2A

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only business guide; it discusses risky agent-commerce patterns but does not run code, request permissions, or access user data.

Safe to install as an informational skill. Before using its advice in a real product, add explicit user authorization for purchases, scoped payment credentials, spending limits, reorder notifications, easy cancellation, audit logs, data minimization, retention limits, and clear privacy notices for any agent or user tracking.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The document explicitly recommends per-query analytics that include persistent agent identifiers, capability queries, selection status, and conversion outcomes, but provides no guidance on consent, minimization, retention, or disclosure. In a discovery/marketing skill, this normalizes covert behavioral tracking and can enable profiling of users or agents across transactions and services.

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The section promotes autonomous reordering as a desirable end state without mentioning approval thresholds, spending limits, fraud checks, or rollback mechanisms. In a skill about optimizing sales to agents, this omission increases the risk of unintended purchases, abuse of compromised agents, and recurring transactions that users did not meaningfully authorize.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly promotes autonomous reordering with 'No human decision point' while omitting safeguards around user consent, spending caps, cancellation, and transparency. In a retail context, this can lead to unauthorized purchases, dark-pattern lock-in, and privacy-invasive monitoring of household consumption without meaningful user awareness.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The replenishment API includes persistent user_id and agent_id identifiers tied to automated ordering behavior, but provides no privacy guidance, minimization, or access-control expectations beyond basic functionality. This creates risk of unnecessary tracking, cross-system profiling, and misuse of subscription/order data if identifiers are exposed, over-retained, or shared too broadly.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The required tracking guidance calls for collecting agent_id, user_id, discovery source, comparison_set, and decision timing, enabling granular attribution and behavioral surveillance without any privacy warning or governance constraints. In this business context, the data model goes beyond operational necessity and can be exploited for user profiling, competitive intelligence gathering, and opaque monitoring of agent-human interactions.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal