Back to skill

Security audit

Card Credits

Security checks across malware telemetry and agentic risk

Overview

This skill gives credit-card statement-credit information using normal web research and does not request account access, persistence, or code execution.

Before installing, understand that the skill will use web research to summarize card credits and may hide source metadata in its structured output. It does not need your bank login or card account access; do not provide credentials, and ask for visible sources if you want to verify terms yourself.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Low
Confidence
81% confidence
Finding
The default prompt demonstrates invocation with a single phrase tied to "American Express Gold Card," but the manifest does not clearly define whether the skill is limited to that card or applies more broadly to any eligible card. This ambiguity can cause unintended or inconsistent invocation scope because users are not given explicit trigger constraints or exclusions.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.