Bank Card Ocr

Security checks across malware telemetry and agentic risk

Overview

This skill does the advertised bank-card OCR, but it uploads the selected card image to SCNet and should only be used with explicit approval.

Install only if you are comfortable sending selected bank-card images and extracted card details to SCNet. Use test or approved images where possible, protect the SCNET_API_KEY, verify the SCNet publisher/source, and require explicit confirmation before running OCR on real payment-card data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The auto-invocation guidance is broad enough that an agent may trigger the skill whenever a user mentions a bank card image path, without strong consent or exclusion rules. Because the skill uploads highly sensitive financial imagery to an external service, overly permissive triggering increases the risk of unintended data disclosure.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal