Back to skill

Security audit

free-tools

Security checks across malware telemetry and agentic risk

Overview

This is a marketing-strategy skill with limited, disclosed local context reading and no code execution, persistence, or hidden data movement.

Before installing, understand that this skill may read a local product-marketing context file if one exists and will give advice about collecting emails for lead generation. Use its lead-capture recommendations with clear user notice, consent where required, retention limits, and applicable privacy or marketing-law review.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger description is very broad and includes many generic marketing terms, which can cause the skill to activate in situations where a more appropriate or safer skill should be used. Over-broad routing increases the chance of misapplication, inappropriate context gathering, and unintended guidance based on stale or mismatched assumptions.

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The skill recommends email collection and lead capture patterns but does not instruct the agent to warn about privacy implications, consent, retention, or applicable legal requirements. In practice this can lead users to design data-collection flows that are non-transparent or non-compliant, especially when collecting contact details in exchange for reports or tool outputs.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The eval explicitly rewards the skill for triggering on a vague, casual request ('give me some ideas for free tools...') without defining stronger routing boundaries or disambiguation checks. In practice, this can cause the skill to over-trigger on broad brainstorming prompts and override more appropriate skills, increasing prompt-routing confusion and making agent behavior less predictable.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.