Back to skill

Security audit

Customer Visit Prep

Security checks across malware telemetry and agentic risk

Overview

This sales-preparation skill is mostly coherent, but it can store customer visit content and send prepared materials through Enterprise WeChat without clear approval steps.

Review before installing in a real sales environment. Use it only if you are comfortable with customer names and sales context being used for web research, customer memory files being read and automatically updated, and documents potentially being sent through Enterprise WeChat. Require manual approval before any memory write or external message send.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
The skill adds a capability to generate documents and send them through WeCom, which exceeds the core scope of preparing visit materials in-chat. This creates an unnecessary data egress path for potentially sensitive customer information without any stated authorization, review, or transport safeguards.

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
Automatically appending visit-preparation content into persistent customer memory introduces a write-side effect beyond the stated preparation function. This can store inaccurate, sensitive, or unnecessary sales data without user review, creating privacy, integrity, and data-retention risks.

Vague Triggers

Medium
Confidence
78% confidence
Finding
The trigger phrases are broad enough to match ordinary sales conversations, increasing the chance the skill activates in situations the user did not intend. Over-broad activation is dangerous here because the skill includes external search, file generation, and persistent-memory behaviors that may run under an overly permissive invocation boundary.

Vague Triggers

Medium
Confidence
76% confidence
Finding
The activation examples describe common, ambiguous requests and do not define when the skill should abstain or ask for confirmation. In a skill with memory access and possible outbound transmission, unclear activation boundaries increase the likelihood of unintentional data processing.

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill states it will automatically write visit-preparation content into customer memory files without any user-facing notice or approval. Silent persistence of customer-related information is a significant privacy and integrity issue, especially in a sales context where notes may contain sensitive commercial details or unverified assumptions.

Missing User Warnings

High
Confidence
96% confidence
Finding
The skill allows generation of documents and transmission via WeCom without warning the user about privacy, sensitivity, or where the data will be sent. This is a clear data-exfiltration and compliance risk because customer research, strategy, and talking points may include confidential business information.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The manifest description appears mojibake/garbled, which prevents reviewers and users from clearly understanding the skill’s purpose, trigger conditions, and operational scope. While this is not an exploit primitive by itself, unclear metadata can hide risky behavior, impair informed consent, and increase the chance that the skill is invoked or trusted in inappropriate contexts.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.