Partnership Revenue Engine

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed business playbook for partnership research and outreach, with no code, hidden automation, persistence, credential access, or destructive behavior in the artifacts.

Before installing, treat this as a business research and outreach assistant. Use only lawful, permitted sources, avoid collecting unnecessary personal data, verify claims before outreach, cite sources where possible, and review generated emails or agreements before sending or using them externally.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The skill explicitly offers to build partner research briefs from web data, including named individuals, LinkedIn URLs, funding, growth, and competitive intelligence, but provides no constraints on lawful collection, minimization, source validation, or handling of personal data. In a business-development context this can normalize scraping, aggregation, and storage of personal/business information without consent or compliance checks, creating privacy, legal, and reputational risk.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal