Buy

Security checks across malware telemetry and agentic risk

Overview

This Markdown-only shopping advice skill matches its stated purpose and shows no hidden execution, credential access, persistence, or authority to make purchases.

Reasonable to install as shopping and negotiation decision support. Treat its recommendations as advice: verify prices and seller legitimacy yourself, keep control of purchases and cancellations, and avoid sharing credentials or unnecessary account details.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
96% confidence
Finding
The activation line includes generic phrases such as "help me find" and "negotiate," plus the broad catch-all "price research requests." These are not narrowly scoped to purchase evaluation and could cause unintended invocation in many ordinary conversations.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal