Back to skill

Security audit

Aws Cost Optimizer Tool Free

Security checks across malware telemetry and agentic risk

Overview

This AWS cost-analysis skill is not malicious, but it asks for AWS credentialed access while its scope and write/exec authority are broader and less clearly bounded than users should accept without review.

Install only if you intend to let the agent use AWS billing/resource read access. Use a dedicated read-only AWS profile or IAM user, avoid production admin credentials, review any command before it runs, and choose explicit report output paths to avoid accidental local file writes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill presents itself as a free, advisory AWS cost-analysis tool, but its declared tools and documented operations include write/modify/import/create/export behavior. That mismatch can cause an agent or user to authorize broader filesystem or action capabilities than expected, increasing the risk of unintended file writes or workflow side effects.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
A cost-analysis skill primarily needs read access to AWS billing data and possibly local report generation, but declaring a general write capability is broader than justified by the stated use case. Excessive capability increases the blast radius if the skill is invoked unexpectedly or if downstream instructions are abused to overwrite local files.

Intent-Code Divergence

Medium
Confidence
93% confidence
Finding
The documentation says the free version does not support automatic optimization or direct execution, yet nearby sections advertise modify/reset/import/create operations. These contradictory claims can mislead users and agent frameworks about the real authority of the skill, enabling broader actions than users reasonably expect.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The activation language is overly broad, including generic data analysis, reporting, statistics, and visualization use cases that are not uniquely tied to AWS cost analysis. This can cause the skill to trigger on unrelated requests, unnecessarily exposing AWS credentialed functionality and local exec capabilities in broader contexts.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The scope statement enumerates an extremely broad set of keywords, including common business-analysis phrases, without meaningful constraints. In an agent ecosystem, this can lead to over-selection of the skill and unnecessary exposure of exec/write-capable behavior in contexts that do not require AWS cost access.

Missing User Warnings

Low
Confidence
80% confidence
Finding
The skill documents export capability but does not clearly warn that exporting creates files on disk. While low severity, silent file creation can still surprise users, affect working directories, or overwrite existing reports if naming/location is not controlled.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The examples tell users to configure AWS credentials but do not clearly warn that the skill will access sensitive account billing and resource metadata through those credentials. This omission weakens informed consent and may lead users to expose production-account financial data without understanding the scope of access.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.