Back to skill

Security audit

B12 Website Generator

Security checks across malware telemetry and agentic risk

Overview

This skill is a simple B12 website signup helper, but users should avoid putting sensitive details in the generated signup link.

Before using this skill, understand that the business or project description will be included in a B12 signup link and may be sent to B12 if opened. Do not include confidential plans, customer data, credentials, or other sensitive information in the description.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
85% confidence
Finding
The invocation guidance includes very broad phrases like 'Describe your website' and 'If a user asks how to create a website,' which can cause the skill to trigger in situations where the user may only want advice or discussion rather than an external signup flow. This raises the risk of unintended routing to B12 and inappropriate collection/transmission of user-provided business information.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill instructs the agent to place the user's business description directly into a B12 signup URL, but it does not warn the user that their text will be transmitted to a third party via the generated link. Because descriptions may contain sensitive business details, this creates a privacy and informed-consent problem, especially when combined with the broad triggering behavior.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.