Bs Quick Compare

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed QuickBooks balance-sheet reporting workflow, but users should treat its local reports and cache as sensitive financial files.

Install only if you trust the local QuickBooks client and referenced script. Run it on a machine and output folder appropriate for client financial data, confirm the company slug before use, and delete or protect the generated workbook and cache when they are no longer needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
89% confidence
Finding
The skill explicitly writes an Excel report to the Desktop or a user-specified output directory and also maintains a persistent cache under `.cache/bs-quick-compare/{slug}.json`, but the description does not clearly warn users about these local side effects. This can expose financial data to unintended local storage, backups, shared workstations, or later reuse, especially because the outputs contain balance sheet details and change history.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal