Back to skill

Security audit

Contract Helper

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed influencer contract drafting and review helper with no executable code, hidden network behavior, or disproportionate authority.

Before installing, understand that the skill can save influencer contract drafts, review memos, and signed deal terms in local memory. Treat its legal output as a drafting aid only and have contracts reviewed by qualified counsel before signing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The phrase 'Auto-activate once a partnership is agreed in principle and the deal needs paperwork' does not define how the system determines that a deal is 'agreed in principle' or what qualifies as 'needs paperwork.' This creates an unclear activation boundary for a manifest/markdown file and could cause unintended invocation in ordinary deal discussion contexts.

Autonomous Decision Making

Medium
Category
Excessive Agency
Content
### 3.5 Content Modifications

Brand [MAY/MAY NOT] modify Content. Any modifications require [written approval from Influencer / no approval].

---
Confidence
22% confidence
Finding
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Scope Creep

Low
Category
Excessive Agency
Content
### 4.2 Competing Brands

For purposes of this Agreement, competing brands include but are not limited to:
- [Competitor 1]
- [Competitor 2]
- [Competitor 3]
Confidence
21% confidence
Finding
Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Scope Creep

Low
Category
Excessive Agency
Content
### 6.1 FTC Compliance

Influencer agrees to comply with all Federal Trade Commission (FTC) guidelines regarding endorsements and testimonials, including but not limited to clear and conspicuous disclosure of the material relationship with Brand.

### 6.2 Required Disclosures
Confidence
21% confidence
Finding
Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Scope Creep

Low
Category
Excessive Agency
Content
### 8.1 Confidential Information

Both Parties agree to keep confidential all non-public information related to this Agreement, including but not limited to:
- Financial terms
- Campaign strategy
- Unreleased products or information
Confidence
21% confidence
Finding
Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Scope Creep

Low
Category
Excessive Agency
Content
### 10.4 Morality Clause

Brand may terminate immediately if Influencer engages in conduct that damages Brand's reputation or is inconsistent with Brand's values, including but not limited to:
- Criminal activity
- Discriminatory behavior
- Controversial public statements
Confidence
21% confidence
Finding
Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.