Back to skill

Security audit

Discovery Call Debrief

Security checks across malware telemetry and agentic risk

Overview

This is a sales debrief skill that processes user-provided call notes into MEDDIC scoring, CRM text, and a follow-up email without hidden execution or data sharing.

Installers should still treat call transcripts as sensitive business data. Use this only with call notes you are allowed to process, review generated CRM updates and emails before sending, and avoid including unrelated legal, medical, or financial details unless you specifically want them handled.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

External Transmission

Medium
Category
Data Exfiltration
Content
## Safety Notes

- Call notes and transcripts contain personal information (names, job titles, company details, budget figures). Do not store, log, or transmit this data beyond the current session.
- Never share debrief outputs with third parties or suggest integrations that would send data to external services without the user's explicit instruction.
- If the transcript contains sensitive legal, medical, or financial information outside the sales context, note it but do not analyze it without the user's direction.

## Feedback
Confidence
70% confidence
Finding
send data to external

Exfiltration Commands

High
Category
Prompt Injection
Content
## Safety Notes

- Call notes and transcripts contain personal information (names, job titles, company details, budget figures). Do not store, log, or transmit this data beyond the current session.
- Never share debrief outputs with third parties or suggest integrations that would send data to external services without the user's explicit instruction.
- If the transcript contains sensitive legal, medical, or financial information outside the sales context, note it but do not analyze it without the user's direction.

## Feedback
Confidence
90% confidence
Finding
send data to external

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.