Privacy Cards

Security checks across malware telemetry and agentic risk

Overview

The skill is coherent and not malicious, but it gives an agent direct production financial-card management commands without enough guardrails for irreversible or sensitive actions.

Review before installing. Use a least-privileged Privacy.com API key, prefer sandbox testing, require explicit confirmation before create/update/close requests, verify the exact card token before closing, and avoid exposing full card numbers, CVVs, or API keys in chats, logs, terminal history, or shared files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill includes a permanent card-closing command and labels it as permanent, but it does not give an explicit warning to confirm irreversibility or recommend a safer temporary alternative first. In an agent skill context, documentation that normalizes destructive financial actions without a confirmation step can lead to accidental irreversible account changes.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal