Back to skill

Security audit

Betting

Security checks across malware telemetry and agentic risk

Overview

This is a transparent betting-analysis skill that stores local notes and includes responsible-use limits, with no code that places bets or accesses accounts.

Install only if you want betting analysis and local tracking. Prefer the explicit activation setting, keep ~/betting/ free of credentials or financial identity details, and do not use it for underage, self-excluded, prohibited-jurisdiction, loss-chasing, or compliance-evasion situations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation rule is broad enough to trigger the betting skill whenever a user casually mentions bets, odds, props, or sportsbooks, even if they are not asking for betting analysis. In a gambling-related skill, unsolicited or overly eager invocation increases the chance the system steers a user toward wagering behavior without clear intent, which is especially risky for vulnerable users or contexts where betting advice should remain opt-in.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.