Back to skill

Security audit

churn-prevention

Security checks across malware telemetry and agentic risk

Overview

This skill is a non-executable SaaS churn-prevention guide whose file access and business recommendations fit its stated purpose.

Before installing, be aware that this skill may help design billing, cancellation, dunning, and customer-retention workflows. Use it with clear user approval before changing subscription behavior, payment retry rules, account access, or customer communications, and review legal requirements for easy cancellation and marketing consent.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The eval explicitly rewards the skill for activating on casual phrasing like a generic question about a cancel button, which broadens routing beyond clear churn-intent signals. Overly broad activation can cause the wrong skill to intercept unrelated requests, leading to mis-scoped guidance, instruction conflicts with more appropriate skills, and reduced reliability of agent behavior.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.