Back to skill

Security audit

Bidding Compliance Advisor 1.3.1

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed bid-compliance checklist assistant with proportionate document review behavior and no hidden execution, persistence, or exfiltration instructions.

Before installing, treat bid documents, pricing, qualifications, and strategy as sensitive business information. Use the skill for formal bid-compliance review, avoid sharing unnecessary confidential pricing details, and verify legal conclusions with current official sources or counsel.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger phrases are broad, natural-language requests such as general bid-preparation help, which can cause the skill to activate during ordinary conversation without clear user intent to invoke this specialized workflow. That increases the chance of unintended routing, over-collection of procurement documents, or the application of rigid compliance instructions in contexts where they do not belong.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.