Back to skill

Security audit

Card Rate

Security checks across malware telemetry and agentic risk

Overview

This skill looks up public credit-card reward rates using web search/fetch, with no install code, persistence, or hidden account actions.

Safe to install based on the visible artifacts. Expect web lookups for current rewards information, and only provide a Brave Search API key if you want that optional search path. Avoid entering account numbers, CVV, logins, balances, or other private financial details; the skill only needs the public card name.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger phrases include generic terms such as "earning rates," "how many points," and "what categories," which can match ordinary conversation unrelated to an explicit request to invoke this skill. Overly broad activation increases the chance the agent will perform web searches and fetch external content unexpectedly, expanding attack surface and causing unintended data exposure or tool use.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal