Back to skill

Security audit

Performance Review Drafter

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward HR drafting skill that asks for performance-review details and produces a draft, with no executable code, persistence, or hidden data movement.

Before using this skill, only provide job-related performance information needed for the review, avoid unnecessary sensitive personal details, and follow your company’s HR, privacy, and legal review process before submitting any final review.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
This markdown skill instructs managers to provide notes, goals data, observations, peer feedback, and development areas about a direct report, which are sensitive HR/personnel data. While the skill labels the output as a draft, it does not warn users about confidentiality, privacy, or the need to avoid sharing unnecessary sensitive personal data when using the tool.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.