Back to skill

Security audit

copywriting

Security checks across malware telemetry and agentic risk

Overview

This is a marketing-copy guidance skill with no executable behavior; the main caveat is that it may activate broadly for website copy tasks and read an optional local marketing context file.

Installers should be comfortable with the skill reading optional product-marketing context files such as `.agents/product-marketing.md` when present. Review those files for sensitive business details before using the skill in shared or external-output workflows.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The manifest description says to use this skill whenever the user wants to "write, rewrite, or improve" copy and includes broad phrases like "help me describe my product" and "use this whenever someone is working on website text that needs to persuade or convert." These triggers are expansive and lack clear exclusion boundaries, increasing the chance of unintended invocation for general writing or product-description requests.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.