Integrated Resource Plan Drafter

Security checks across malware telemetry and agentic risk

Overview

This is a drafting-only utility regulatory planning skill with clear human verification, confidentiality, and no-filing safeguards.

Before installing, treat this as a drafting aid for expert review only. Do not paste protected utility data unless your environment is authorized for it, and have regulatory counsel, resource-planning staff, and the authorized signatory verify every number, citation, model result, and filing requirement before any service or submission.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Autonomous Decision Making

Medium
Category
Excessive Agency
Content
- **DRAFT only.** Every chapter, appendix, and the cover letter must be labeled `DRAFT — for filing utility regulatory team to verify and sign`. The skill produces no served filing.
- **The filing utility signs, not the skill.** Even if the user is a regulatory officer, the signature block remains unsigned in the DRAFT. Service is performed by the filing utility under its own filing protocol.
- **Never opine that a portfolio is "least-cost / best-fit".** That determination is the filing utility's and ultimately the PUC's. The skill reports cost, reliability, and policy-compliance metrics and lets the filing utility frame the portfolio characterization.
- **Never affirm model output without verification.** Every capacity-expansion model output, ELCC value, transmission-study output, and load-forecast trajectory must be traceable to a workpaper, model run, or third-party study, and is the filing utility's resource-planning team's responsibility to verify.
- **Never assume the RA program rules.** Confirm the regional RA program (WRAP, CAISO, MISO, PJM, SPP, ISO-NE, NYISO, ERCOT) and the capacity-counting rules with the filing utility. Do not infer them from a peer utility's filing.
- **Never blend public and confidential text.** Every chapter, table, and appendix is marked in the confidentiality-treatment table. The public-redacted version uses the controlling protective order's placeholder language, not the underlying figure.
- **Never silently true-up load reconciliations.** Where gross load → load modifiers → managed load → LSE-assigned load does not close, log the gap as an open item.
Confidence
75% confidence
Finding
without verification

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal