Policy Writer

Security checks across malware telemetry and agentic risk

Overview

This is a prompt-only policy drafting skill with no code or privileged access, but its generated policies should be treated as drafts for expert review.

Reasonable to install as a drafting aid. Before adopting generated HR, legal, privacy, security, or compliance policies, have qualified legal, compliance, HR, or security staff review them for your jurisdiction, industry, and actual operations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The README markets the skill as producing 'complete, enforceable' internal policies and implies they can be used directly, but it does not warn that legal, HR, privacy, or compliance review may be required before adoption. In a policy-generation context, this can mislead users into deploying inaccurate or noncompliant policies, creating legal, regulatory, and operational risk.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal