Conversation Summarizer

Security checks across malware telemetry and agentic risk

Overview

This instruction-only skill summarizes conversation text; the main caution is that users may paste private chats, emails, or support records into it.

Before using this skill, redact secrets, credentials, regulated personal data, customer information, and confidential business details from transcripts, chats, emails, and support tickets. Review generated quotes, action items, and summaries before sharing or saving them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill is explicitly designed to process meeting transcripts, chat logs, email threads, and support tickets, which commonly contain sensitive personal, business, or customer data. Because the skill description and guidance do not warn users to avoid secrets/PII or to sanitize content before submission, it creates a real privacy and data-handling risk, especially in enterprise or support contexts.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal