Skylv Cost Guard

Security checks across malware telemetry and agentic risk

Overview

This is a local AI API cost-tracking helper with broad activation wording but no evidence of hidden network access, credential use, or destructive behavior.

Install only if you want a local, manual AI API cost tracker. Run it in a directory where creating .cost-guard.json is acceptable, treat that file as private usage and spend history, and verify current provider pricing separately before making billing decisions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger keywords are very broad terms like 'cost', 'budget', 'optimize', and 'spend', which are common in normal conversation and can cause accidental invocation. This increases the chance the skill activates in unrelated contexts, exposing user data or causing unintended actions when the user did not mean to engage this skill.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The example invocations like 'how much have I spent?' and 'optimize my API spending' are ambiguous and resemble everyday assistant requests rather than explicit skill activation. In an agent ecosystem, unclear boundaries can cause the skill to intercept general financial or usage-related queries, leading to unintended execution or disclosure of usage data.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal