PC Game Deals

Security checks across malware telemetry and agentic risk

Overview

This is a simple PC game deal lookup skill that uses CheapShark with curl and jq and does not request sensitive access.

Before installing, understand that game titles or deal queries may be sent to CheapShark over the network. Use the optional price-alert flow only if you are comfortable entering an email address on CheapShark's website.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The manifest description includes broad triggers like mentions of 'game prices/savings', which can cause the skill to activate for general pricing discussions rather than clear PC game deal requests. This can lead to inappropriate tool selection, unnecessary external API calls, and accidental disclosure of user intent to a third-party service when the user did not explicitly ask for game deal lookup.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal