Back to skill

Security audit

content-strategy

Security checks across malware telemetry and agentic risk

Overview

This content strategy skill is a read-only planning guide with a narrow, disclosed local-context check and no evidence of hidden, destructive, or persistent behavior.

Install this if you are comfortable with the agent using existing product-marketing context files in your workspace to avoid asking duplicate business-context questions. Avoid placing unrelated sensitive material in those specific files if you do not want it used for content strategy work.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
94% confidence
Finding
The skill explicitly instructs the agent to read local project files such as `.agents/product-marketing.md` before asking the user questions, without requiring consent or notifying the user. This can lead to unintended access to potentially sensitive internal business context and incorporation of that data into responses, especially when the user did not request file inspection or may not realize local files will be read.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.