Invoice Tracker Pro

Security checks across malware telemetry and agentic risk

Overview

This is a plain invoicing helper whose sensitive billing reminders and payment examples are disclosed and aligned with its purpose.

Install only if you are comfortable using an assistant for billing work. Review every invoice, reminder email, late fee, payment link, tax summary, and client recipient before sending or acting, and avoid providing unnecessary bank details, tax IDs, or client personal information.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill promotes automated reminders and payment auto-charging workflows without clearly requiring user confirmation, authorization checks, or warnings before contacting clients or initiating charges. In a billing context, this can lead to unintended external actions, unauthorized payment attempts, reputational damage, disputes, or financial harm if an agent executes these steps too aggressively or without proper consent.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal