Tiktok Affiliate Roi Calculator

Security checks across malware telemetry and agentic risk

Overview

This is a small instruction-only ROI calculator skill with no hidden access, persistence, or executable install behavior.

Before installing, confirm that the non-commercial license fits your use and avoid entering confidential business data unless you are comfortable sharing it with the agent context. If you prefer English or another language, tell the agent before using the skill.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The skill instructs the agent to begin interaction in Chinese ('先交互,再计算' and the numbered prompts) without offering a language-choice fallback. This can cause unintended language switching, reduce user comprehension, and create operational risk if users misunderstand financial assumptions or recommendations in an ROI calculation context. While not a code-execution issue, it is a real safety and usability vulnerability because it can lead to incorrect business decisions based on misunderstood inputs.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal