Token Cost Optimization

Security checks across malware telemetry and agentic risk

Overview

This is a coherent token-cost calculator and optimization guide, with a privacy caution around optional document caching advice.

Safe to install as a local calculator and reference guide. If you follow the vector-database caching advice, get user or organizational approval first, avoid indexing secrets or sensitive documents unless necessary, and define encryption, access controls, retention, and deletion procedures.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The use-case trigger list is broad enough that the skill may activate during ordinary discussion about tokens, pricing, or compression rather than when the user explicitly requests this skill. Overbroad activation can cause unintended context injection, unnecessary tool suggestions, or skill interference, which is a security and reliability issue in agentic systems even though the content here is not directly dangerous.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The guidance recommends storing user-provided documents in a vector database for later retrieval, but it omits any mention of consent, access controls, retention limits, encryption, or handling of sensitive data. In a cost-optimization skill, this can normalize persistent storage of potentially confidential user content purely for efficiency, creating privacy, compliance, and data-exposure risks if adopted without safeguards.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal