Designer Toys

Security checks across malware telemetry and agentic risk

Overview

The available evidence shows a coherent shopping/trend-oriented skill with only a routing-quality concern, not harmful behavior.

This looks acceptable to install if you want help with niche trend-toy, collectible, pop-up, or shopping-related planning. Be aware it may activate for broader travel or itinerary requests than intended, so confirm the agent is using it only when that shopping/collectible context is relevant.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill description is broad enough to match generic travel-planning requests, which can cause the agent to invoke this skill outside its intended niche. Over-broad routing can misdirect users, produce irrelevant recommendations, and crowd out more appropriate skills, reducing reliability and potentially affecting downstream decisions such as travel planning or purchases.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal