Knowledge Management System

Security checks across malware telemetry and agentic risk

Overview

This appears to be a documentation-focused knowledge management skill, with privacy cautions around credentials and internal sources but no evidence of hidden or harmful behavior.

Install if you want an agent to help structure organizational knowledge and documentation. Do not paste raw credentials or secrets into generated docs, and only let it use Slack, meeting notes, or internal documents that are approved for the intended audience.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The interview guide explicitly asks for 'tools, credentials, or access' needed to perform a process, but provides no instruction to avoid recording secrets or to use secure secret-management references instead. In a knowledge-management skill, users may copy passwords, tokens, or privileged access details into durable documentation, creating unnecessary exposure and long-lived credential leakage risk.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The chatbot design includes Slack-sourced answers and meeting notes as searchable knowledge sources without any privacy, classification, or redaction controls. Those sources commonly contain credentials, customer data, HR discussions, incident details, or legal-sensitive material, so indexing and surfacing them via chat can broaden access and leak sensitive information to unintended audiences.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal