投放素材效果诊断

Security checks across malware telemetry and agentic risk

Overview

This appears to be a purpose-aligned advertising report analysis skill, with a privacy caution around optional sharing to Feishu or email.

Install only if you are comfortable using it on advertising performance data. Review generated reports before sending them externally, confirm the destination and audience for Feishu or email sharing, and avoid including secrets, personal data, or confidential metrics unless sharing is explicitly approved.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill states that the generated report or enriched recommendations may be sent through other channels such as Feishu or email, but it does not present a clear warning, consent flow, or boundary on what data may be shared externally. Because the analyzed inputs are advertising performance reports that may include commercially sensitive metrics, external transmission increases confidentiality risk beyond the local analysis context.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal