Back to skill

Security audit

Ntriq X402 Invoice Extract Batch

Security checks across malware telemetry and agentic risk

Overview

This skill is a simple documented API guide for paid invoice and receipt extraction, but users should understand that document URLs and extracted financial data go to a third-party service.

Install only if you are comfortable sending invoice or receipt image URLs, and likely their fetched contents and extracted fields, to x402.ntriq.co.kr. Avoid regulated, confidential, customer, or payment-sensitive documents unless you have authorization and understand the service’s retention and logging practices.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs users to send invoice/receipt image URLs to a remote third-party endpoint and receive extracted financial document data, but it does not clearly warn that potentially sensitive business and financial information leaves the local environment. Invoices and receipts commonly contain personal data, billing details, tax IDs, addresses, and payment information, so omission of a prominent disclosure can lead to unintentional data exposure and non-compliant handling of sensitive documents.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal