Newsletter Creation Curation

Security checks across malware telemetry and agentic risk

Overview

This appears to be a newsletter-writing workflow skill with no evidence of data theft, destructive actions, or hidden execution, though its broad activation setting deserves user awareness.

Before installing, be aware that this skill may be considered for more interactions than just explicit newsletter requests. Install it if you want reusable newsletter workflow guidance, but remove or narrow the always-on trigger if you only want it active when you specifically ask for newsletter creation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

High
Confidence
97% confidence
Finding
The manifest metadata includes `always:true`, which causes the skill to be considered for every interaction rather than only when explicitly relevant. In a content-generation skill like this, broad automatic activation increases the chance the agent injects unsolicited marketing, geography-specific assumptions, or workflow guidance into unrelated tasks, expanding attack surface and reducing user control.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal