PCI DSS Checker

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward PCI DSS self-assessment API skill, but users should avoid sending overly detailed or sensitive company security information unless they trust the provider.

Use this as an advisory self-assessment, not formal PCI validation. Before submitting real company details, verify the API provider and avoid including card numbers, sensitive authentication data, secrets, customer data, logs, network diagrams, or exact system identifiers; prefer minimized or anonymized answers where possible.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly solicits detailed PCI-scoped environment information, including whether cardholder data is stored, transmitted, encrypted, segmented, logged, and protected by specific controls, yet provides no warning about sensitivity, data minimization guidance, retention policy, or handling restrictions. In context, this is dangerous because the collected answers effectively map an organization's cardholder data environment and control gaps, creating a high-value target profile if sent to or retained by an external service.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal