Back to skill

Security audit

Bill Monitor

Security checks across malware telemetry and agentic risk

Overview

This bill-monitoring skill is useful and not malware, but it needs review because it scans Gmail and stores household financial details without clearly bounded consent or deletion controls.

Review before installing. Use only in a private workspace, confirm exactly which Gmail account and search scope it can access, verify alerts go only to a private channel, and make sure you know how to pause monitoring and delete bills.md/config.md.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The skill states that bill data is 'never shared externally,' but its switch-advisor feature explicitly performs external web searches using bill type and the user's region. That creates a misleading privacy guarantee and risks transmitting sensitive financial context to third-party services without clear disclosure or consent.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger list includes broad phrases such as 'energy bill' and 'utility costs,' which can cause the skill to activate in contexts where the user did not intend bill monitoring. Because this skill handles financial and email-derived data, accidental invocation increases the chance of unnecessary sensitive-data access or disclosure.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill instructs the agent to scan Gmail for bills and extract amounts/providers, but it does not require an explicit warning or consent flow for accessing highly sensitive email and financial information. In practice, this can lead to overcollection of personal data and surprise access to mailbox contents beyond what the user reasonably expected.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.