name: cccfindg

Security checks across malware telemetry and agentic risk

Overview

This skill is a corporate address-book lookup that can expose employee IDs and phone numbers, including through repeated or paginated searches, without enough privacy guardrails.

Install only if you are authorized to access this internal address book and disclose employee contact details. Use narrow, business-justified queries, avoid bulk lookups, and do not share or retain returned employee IDs, desk phones, or mobile numbers outside approved channels.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill is designed to retrieve and output employee directory data, including employee IDs, landlines, and mobile numbers, without any privacy notice, access-control check, or data-minimization step. In the context of an enterprise address book, this increases the risk of unnecessary disclosure of internal PII to users who may not have a legitimate need to access all requested fields.

Ssd 3

Medium
Confidence
97% confidence
Finding
The skill explicitly instructs the agent to extract and present directory PII such as employee numbers and phone numbers in the final output. In an internal directory context, this makes the skill more dangerous because it operationalizes bulk or repeated disclosure of employee contact data without safeguards, enabling privacy violations, social engineering, and internal reconnaissance.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal