Back to skill

Security audit

Bid Compliance Due Diligence V2

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed public-record bid-compliance due-diligence workflow, with some privacy and reputational considerations but no hidden install, persistence, credential use, or destructive behavior.

Before installing, be aware that this skill performs live public-record searches about companies and, by default, their legal representative and largest shareholder. Use it for legitimate procurement or supplier risk review, consider disabling related-party penetration when unnecessary, and manually verify high-impact decisions with counsel or official records.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
85% confidence
Finding
The trigger examples are broad everyday phrases such as asking whether a company is 'reliable' or 'has problems', which can cause the skill to activate outside a clearly bounded procurement-compliance context. In an agent environment, overbroad activation can route unrelated company-due-diligence queries into a high-authority compliance workflow, increasing the chance of unintended data gathering, misclassification, or user confusion.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are broad enough to match ordinary due-diligence or vendor-screening requests, which increases the chance the skill activates when a user did not specifically intend a live compliance investigation. In this skill, unintended activation is more sensitive because it can launch web searches and analyze negative records about companies and related persons, creating privacy, reputational, and consent risks.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The description says the skill uses WebSearch/WebFetch and may penetrate into legal representative and major shareholder records, but it does not present this as a clear user-facing warning or obtain explicit acknowledgment. That is dangerous because users may unknowingly cause collection and analysis of third-party and related-person data, including potentially sensitive adverse records, without informed consent or clear scope awareness.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.