Back to skill

Security audit

Business Tools Pack

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed business automation skill pack, but users should apply privacy, platform, and anti-spam safeguards before using its research or email features.

Before installing, treat this as a business automation pack that can touch public web data, customer contact data, and email platforms. Use it only with sources and accounts you are authorized to access, review platform terms, minimize personal data collection, use scoped API keys, and require human approval before any outbound email or customer-facing workflow goes live.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The README advertises scraping Reddit, forums, and competitor sites without any mention of consent, terms-of-service restrictions, rate limiting, or handling of collected personal data. In a business automation pack, this omission can lead users to deploy scraping against third-party services in ways that violate platform rules or collect personal information without adequate safeguards.

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The README states that the skill can deploy email sequences directly to ConvertKit or Mailchimp, but does not warn that it may configure or send outbound customer communications. That creates a meaningful risk of unauthorized mass outreach, accidental spam, or regulatory noncompliance if users do not understand that live mailing infrastructure may be affected.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
Automated post-purchase follow-up emails and reinjection of collected reviews into a pipeline involve customer contact data and user-generated content, yet the README gives no warning about data handling, consent, retention, or automation of outreach. In this context, the feature could expose businesses to privacy complaints, unwanted communications, or unsafe reuse of customer data across downstream systems.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.