Quick Converter

Security checks across malware telemetry and agentic risk

Overview

Quick Converter is a simple offline conversion helper with no code or permissions, though its money, crypto, and timezone results are only rough estimates.

Safe to install for casual offline conversions. Before relying on time, currency, or crypto answers, check the assumed timezone and verify current financial values with a live trusted source.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The skill documentation explicitly defaults time calculations to IST and an Ahmedabad/Gujarat context without requiring user confirmation. This can cause incorrect outputs for users in other regions, leading to misleading scheduling, deadline, or event calculations; while not a direct code-execution issue, it is a genuine safety and reliability problem because the agent may present locale-specific assumptions as generally applicable.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal