Employee Handbook Generator

Security checks across malware telemetry and agentic risk

Overview

This instruction-only handbook drafting skill is coherent and low risk, but its HR/legal output should be reviewed before use.

Install if you want an agent to draft employee handbook materials. Provide only company details you are comfortable sharing with your agent, and have HR or legal counsel review the result before distributing it to employees, especially for jurisdiction-specific policies.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The skill says 'When activated, the agent asks for...' but does not define explicit trigger phrases, scope boundaries, or when the skill should or should not run. In an agentic system, vague activation can cause the skill to engage on loosely related HR or policy prompts, leading to unintended disclosure of sensitive company details, generation of authoritative-sounding legal/HR guidance outside user intent, or prompt-routing confusion with other skills.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal