Email Capture Generator

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward marketing template skill for email capture pages, with ordinary privacy and publishing hygiene risks but no hidden execution or data theft behavior.

Install only if you are comfortable using a marketing-page generator that helps collect visitor emails. Before publishing generated pages, use a trusted HTTPS form endpoint, escape substituted template values, provide real privacy and terms links, include clear consent and unsubscribe language, and verify testimonials, subscriber counts, deadlines, and security claims.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The example explicitly captures email addresses for a lead magnet but only provides vague reassurance like 'No spam' and 'Your email is 100% secure' without clearly disclosing what data is collected, how it will be used, who processes it, or whether users will receive marketing follow-up. In a funnel-generation skill, this omission can propagate non-compliant or deceptive signup flows and increase privacy, consent, and regulatory risk.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal