Back to skill

Security audit

cost-guard

Security checks across malware telemetry and agentic risk

Overview

This is a Markdown-only cost-control helper that may add extra confirmation steps but does not contain hidden execution, credential access, persistence, or data exfiltration behavior.

Install if you want an agent to pause and estimate costs before potentially expensive tasks. Expect it to sometimes interrupt vague or file-heavy requests with clarification and confirmation prompts; there is no evidence here of hidden code execution, credential access, persistence, or exfiltration.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger list contains very broad natural-language phrases that are likely to appear in many unrelated conversations, which can cause the skill to activate when the user did not intend to invoke it. Unintended activation can disrupt normal workflow, inject extra confirmation steps, and steer users into this skill’s logic instead of the most appropriate tool or skill.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation rules are vague and expansive, covering broad categories like file handling, batch generation, agent tasks, or any unclear request. This makes the skill prone to over-triggering on ordinary work, which can create denial-of-service-like friction by forcing unnecessary gating, confirmations, and workflow changes.

VirusTotal

57/57 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.