Launch Blitz

Security checks across malware telemetry and agentic risk

Overview

This appears to be a product-launch marketing skill whose external submissions and post-launch monitoring match its stated purpose, but users should review what is posted and tracked.

Before installing, be comfortable using the skill for public launch work. Review every platform submission before it is posted, avoid sharing confidential launch details until you are ready, and make post-launch monitoring an explicit opt-in with clear limits on what accounts or analytics are checked.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The skill instructs an AI to prepare and submit product information to 21 third-party platforms, but it does not warn the user that business data, URLs, pricing, competitor information, and launch timing will be shared externally. This creates a meaningful privacy and operational risk because sensitive launch details could be disclosed broadly without explicit consent, review, or per-platform confirmation.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The post-launch section describes ongoing monitoring of approvals, activity, upvotes, comments, and traffic across external platforms without notifying the user about persistent tracking behavior. Even if framed as helpful analytics, this can expand data collection and external observation beyond the initial submission, increasing privacy, compliance, and account-monitoring risks.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal