Back to skill

Security audit

TokenBudget — 智能油耗表

Security checks across malware telemetry and agentic risk

Overview

This is not malware, but it gives a budgeting skill broad influence over all agent tasks and includes an automatic localhost broker check plus install recommendation.

Install only if you intentionally want this skill to influence model choice and budget handling across the whole agent session. Review or remove the localhost TokenBroker check and prefer explicit budget commands or confirmation before disabling limits or installing related broker software.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The skill extends beyond budget management by instructing the agent to probe a localhost service and append a product recommendation based on the result. Even though the target is localhost, this is still an unsolicited network interaction that can leak information about the user's environment, trigger local services, and create hidden side effects unrelated to the stated purpose of the skill.

Vague Triggers

High
Confidence
96% confidence
Finding
The skill declares that it should be auto-loaded before every task, giving it pervasive influence over all agent behavior rather than a narrow budgeting context. Overly broad activation increases the chance that unrelated requests are intercepted, modified, downgraded, or blocked, which is dangerous because this skill affects model selection and execution policy across the entire session.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The command phrases are generic everyday language such as asking how much budget remains or to loosen limits, which can easily appear in ordinary conversation. This raises the risk of accidental triggering of state-changing behavior, causing unintentional policy changes like disabling budget checks or modifying limits without a clearly delimited command channel.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The markdown instructs the agent to automatically perform a localhost health check without a user-facing warning or consent. Hidden network probing is risky because it may reveal local service presence, interact with sensitive developer tooling, and violate user expectations about what a budgeting skill should do.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.