Agency Growth Automations

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed, instruction-only methodology skill for agency automation, with no embedded code or hidden install behavior.

Before using the paid workflow pack or sample workflow, review the n8n JSONs for unexpected webhooks, scripts, or outbound destinations; use least-privilege OAuth/API scopes; test with dummy data; and make sure any outreach complies with consent, opt-out, rate-limit, CAN-SPAM/GDPR/ePrivacy, and platform anti-abuse rules.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill promotes automated cold outreach, follow-up automation, and use of Gmail OAuth/Airtable without any guidance on safe handling of personal data, account credentials, consent, rate limits, or anti-spam/legal compliance. This can lead users to deploy workflows that process prospect data and send messages in ways that create privacy, security, and compliance risks, especially because the content frames the workflows as ready-to-deploy business automation.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal