Back to skill

Security audit

Launch Monitor

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed launch-monitoring helper that fetches public/platform launch telemetry and saves user-approved summaries without hidden or destructive behavior.

Before installing, expect the skill to fetch public launch-platform data and ask you for KPI targets or analytics exports when connectors are unavailable. Only provide platform tokens or analytics data you are comfortable using for launch monitoring, and review any requested memory saves before approving them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Low
Confidence
85% confidence
Finding
The display name mixes English with Chinese ("发布窗口监控"), which introduces a locale-specific presentation in the skill definition. The file does not state that this is optional, user-selected, or required for a region-specific purpose, so it can be read as a fixed language choice without opt-in.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.