Back to skill

Security audit

Business Tools Pack

Security checks across malware telemetry and agentic risk

Overview

This appears to be a documentation-only business automation skill bundle, with no executable code, but users should be careful before using related email or scraping workflows on live data.

Before installing or using the related tools, confirm which accounts they connect to, keep email workflows in draft or sandbox mode until reviewed, require explicit approval before sending to real customer lists, and only collect data from sources where you have permission and a lawful reason to process it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The README promotes automated email deployment and follow-up messaging to real customer lists without any warning that actions may send live communications, create spam/compliance risk, or affect production marketing systems. In an agent skill context, this increases the chance of unintended outbound messages, reputational harm, unsubscribe complaints, or violations of email platform and consent requirements.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The README advertises scraping Reddit, forums, and competitor sources without any guidance on site terms, privacy obligations, or safe handling of collected data. This can encourage operators to gather personal or restricted content in ways that violate platform rules, create legal/privacy exposure, or feed sensitive data into downstream automation.

VirusTotal

No VirusTotal findings

View on VirusTotal

Static analysis

No suspicious patterns detected.