Hiveage

Security checks across malware telemetry and agentic risk

Overview

This is a legitimate-looking Hiveage billing integration, but it gives an agent broad access to create, update, delete, and proxy authenticated requests against financial records without clear safety controls.

Review before installing. Use a limited Hiveage account if possible, require clear confirmation before any create, update, payment, recurring-billing, proxy, or delete action, and avoid raw proxy requests unless you have checked the exact endpoint and method.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly documents a destructive `Delete Invoice` action but provides no guidance to require user confirmation, verify intent, or apply safeguards before execution. In an agent setting, this increases the risk of accidental or overbroad destructive operations against financial records, especially if a model maps a user request imprecisely or acts on ambiguous instructions.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal