Funding

Security checks across malware telemetry and agentic risk

Overview

This is a text-only fundraising advice skill with no executable code or system access, but users should review any generated fundraising materials carefully before sharing them.

Reasonable to install as an advisory drafting skill. Fact-check claims, financial projections, traction metrics, donor-impact statements, investor-interest references, legal terms, and risk disclosures before sending materials to investors, donors, crowdfunding platforms, or the public.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger conditions are very broad and include common phrases like "I need to raise money" or general fundraising-related scenarios, which can cause the skill to activate in conversations where the user did not intend to invoke specialized fundraising persuasion guidance. In this context, over-triggering increases the chance the agent will steer ordinary financial, nonprofit, or investment discussions into capital-raising advice, potentially producing unwanted or higher-risk persuasive content without clear user intent.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal