Back to skill

Security audit

PDF Document Generation

Security checks across malware telemetry and agentic risk

Overview

This CellCog document generator is coherent, but it can send sensitive resumes, contracts, legal, finance, and business document contents to an external service without clear consent or data-handling guidance.

Review before installing. Use it only when you are comfortable having the document prompt and supplied materials processed by CellCog, and avoid submitting secrets, regulated data, confidential contracts, personal records, or client financial information unless your organization has approved that use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The skill presents broad, natural-language document creation examples that overlap with common user requests without defining clear routing boundaries or trigger conditions. That can cause the agent to invoke this external-service skill for generic requests and unintentionally send user-provided content, including sensitive business, legal, HR, or personal data, to CellCog when the user may not expect third-party transmission.

Missing User Warnings

High
Confidence
97% confidence
Finding
This skill advertises generation of resumes, contracts, NDAs, invoices, legal documents, and other professional materials via an external API but does not warn that prompts and uploaded content may be transmitted to a third-party service. Because these document types commonly contain personal, financial, confidential, or regulated information, omission of a disclosure materially increases the risk of unintended data exposure and compliance violations.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.