Agent Memory for Commerce

Security checks across malware telemetry and agentic risk

Overview

This is a non-executing educational guide whose commerce-memory and payment-state examples are disclosed and aligned with its stated purpose.

Install this only if you intend to build commerce agents using GreenHelix-style APIs. Use sandbox or least-privilege credentials first, do not provide production payment keys until you have reviewed the examples, and define clear approval gates, retention limits, deletion workflows, access controls, and rules for redacting customer data before using it with real transactions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The guide strongly promotes storing customer history, transaction state, compliance records, and cross-agent sharing, but it does not present a clear up-front privacy warning, minimization policy, or consent boundary. In a commerce context this is sensitive financial and identity-linked data, so omission of privacy constraints can lead developers to over-collect, over-retain, and over-share customer information.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal