Back to skill

Security audit

popups

Security checks across malware telemetry and agentic risk

Overview

This is a popup optimization guidance skill with no executable code, persistence, credential handling, or hidden high-impact behavior.

Before installing, be aware that this skill may activate for a wide range of popup, overlay, banner, or modal conversion requests. Its behavior is advisory and low-risk, but users who rely on multiple marketing skills may want clearer routing boundaries between popup work, general CRO, lead magnets, and form optimization.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The skill description contains a very broad set of trigger phrases and a catch-all clause ('any overlay or interrupt-style conversion element') that can cause the agent to invoke this skill in situations only loosely related to popup optimization. Over-broad routing increases the chance of misclassification, inappropriate guidance, and accidental precedence over more specific skills such as CRO or form-related workflows.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The eval explicitly rewards the skill for triggering on casual phrasing, which broadens activation beyond clearly scoped user intent. In a routing or skill-selection system, overly broad triggers can cause the popup skill to activate for ambiguous requests, increasing the chance of inappropriate guidance, misrouting away from better-matched skills, and unsafe or low-quality downstream behavior.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.