Wishlist

Security checks across malware telemetry and agentic risk

Overview

This skill appears to keep a local wishlist and check configured store prices, with no evidence of harmful or deceptive behavior.

Install this if you are comfortable with the agent creating and maintaining ~/wishlist/ and using product or store lookup queries for price checks. Avoid storing sensitive purchase notes there on shared machines unless you want that information kept locally.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly instructs creation of a workspace under ~/wishlist/ but does not warn the user that files will be created and updated in their home directory. This can lead to unexpected persistence of personal shopping preferences, links, and notes, which is a privacy and consent issue, especially on shared machines or in environments where filesystem writes should be minimized.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal