Data Privacy & Protection Program

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only privacy compliance guide with no code execution, credentials, persistence, or hidden data access.

This skill is reasonable to install as a privacy-program reference, but treat it as guidance rather than legal advice. Because privacy and breach workflows can involve sensitive facts, avoid pasting unnecessary personal data, credentials, or confidential incident details, and have qualified privacy counsel or an authorized human review DSAR responses, breach notifications, and regulatory decisions before acting.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill defines very broad natural-language triggers such as "Help with a DSAR" and especially "We had a data breach," instructing the agent to switch into high-impact operational modes based on ordinary conversation. Because these phrases can appear in quoted text, examples, or ambient discussion, an upstream orchestrator may invoke the skill unintentionally, causing privacy/compliance workflows or urgent incident-response guidance to activate out of context.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal