Back to skill

Security audit

Trend Spotter

Security checks across malware telemetry and agentic risk

Overview

This skill is a marketing trend-report helper with disclosed local memory writes and no evidence of hidden, destructive, or credential-seeking behavior.

Before installing, be aware that trend reports and selected conclusions may be saved into project memory. Review or delete those memory files if you do not want brand plans, audience assumptions, or trend recommendations retained.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
96% confidence
Finding
The manifest says to auto-activate when a request is about 'what is trending, what to post around, or when to act.' Phrases like 'what is trending' and especially 'what to post around' are broad enough to match many ordinary brainstorming requests, and the file does not give clear exclusion boundaries beyond a couple of adjacent skills.

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The markdown explicitly states that the skill writes a trend report to `memory/influencer/trend-spotter/...` and promotes facts to `memory/hot-cache.md`, which affects persistent user/project data. The document presents this as contract behavior but does not clearly warn the user that their inputs and generated conclusions will be stored in memory files.

VirusTotal

58/58 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.