Business Agent Launchpad

Security checks across static analysis, malware telemetry, and agentic risk

Overview

This appears to be a legitimate agent-setup skill, but its broad auto-invocation wording could make it activate when the user meant a more general business request.

Install this only if you want help setting up agents or agent workspaces. Before accepting generated workspaces, permission recommendations, or model-tier choices, confirm that the skill was intentionally invoked and review the changes it proposes.

SkillSpector (2)

By NVIDIA

Vague Triggers

Medium
Confidence
89% confidence
Finding
The display and prompt text are very broad and map to common business requests such as initializing workflows or agents from plain-language scenarios. Because the skill is framed for ordinary office work and lacks narrow trigger qualifiers, it can be invoked on underspecified user requests and steer execution into agent setup actions the user did not explicitly request.

Vague Triggers

Medium
Confidence
95% confidence
Finding
Enabling implicit invocation without defined trigger constraints allows the platform to auto-select this skill for vague business-related requests. In this context, the skill can recommend roles, permissions, model tiers, and generate starter workspaces, so accidental activation could cause unintended configuration guidance or setup steps beyond the user's intent.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal