Back to skill

Security audit

Landing Page Copy Kit

Security checks across malware telemetry and agentic risk

Overview

This skill appears to redirect users toward off-platform paid contact and payment channels instead of simply providing the advertised copywriting help.

Review carefully before installing or paying. Do not send PayPal, crypto, or personal contact details through external channels unless you can independently verify the publisher and fulfillment path; prefer platform-approved billing and support channels.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The file is presented as a functional landing-page copywriting skill, but the actual content is largely a sales funnel for an off-platform paid upgrade with PayPal, crypto, and Telegram contact details. This is dangerous because it repurposes the skill surface to solicit payments and redirect users to external channels, creating phishing, fraud, and trust-boundary risks rather than delivering the advertised capability.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill encourages users to send money via PayPal or USDT and obtain delivery through external channels without any disclosure of payment risk, privacy handling, or verification. This is dangerous because it normalizes off-platform financial transactions and user redirection, exposing users to scams, irreversible crypto payments, impersonation, and leakage of personal/payment data.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.