Tokenguard Pro

Security checks across malware telemetry and agentic risk

Overview

The skill has a reasonable cost-optimization purpose, but it asks to install a missing global command and analyze sensitive session logs without enough privacy scoping.

Review this version before installing. Ask the publisher to include the missing tokenguard-analyze source and document exactly which logs are read, whether processing stays local, and how reports should be protected. If using a corrected version, run it only on minimized or redacted logs and treat generated reports as sensitive.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
This markdown file says the skill analyzes session logs, tool call sequences, model usage, and context growth, which can expose user prompts, workflow details, or other sensitive usage data. The description does not include any user warning or privacy disclosure about inspecting potentially sensitive logs, even though markdown files should warn about behaviors that may affect user data or privacy.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal