Regulatory Affairs Head

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent regulatory-support toolkit with a local submission tracker, not a hidden or unsafe automation package.

Install only for regulatory work where local storage of submission-tracking details is acceptable. Treat any generated regulatory_submissions.json file as confidential, keep it in the intended project folder, and protect or exclude it according to your organization’s data-handling rules.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
83% confidence
Finding
The script persists regulatory submission records to a local JSON file without any notice, consent flow, or safeguards around storing potentially sensitive business data and personal identifiers such as responsible_person, product_name, notes, and regulatory strategy details. In a regulatory affairs context, these records can include confidential commercial information and employee data, so silent plaintext storage increases the risk of unauthorized disclosure if the host is shared, compromised, or backups/logging expose the file.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal