Expense Snap

Security checks across malware telemetry and agentic risk

Overview

Expense Snap is a local expense-tracking skill whose Python, SQLite, and CSV behavior matches its stated purpose.

Install if you are comfortable storing receipt and spending details locally. Keep CSV exports in a trusted folder, avoid putting secrets or full account numbers in notes, and review the export path before running the command.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding
The skill invokes Python scripts, writes to a local SQLite database, and exports CSV files, which clearly require shell execution and file-write capabilities. Failing to declare these permissions weakens transparency and policy enforcement, so an agent or reviewer may authorize the skill without understanding its ability to modify local files.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal