Back to skill

Security audit

mc-monthly-visitor-report

Security checks across malware telemetry and agentic risk

Overview

The skill is coherent for generating marketing reports, but it bulk exports identifiable customer and recording transcript data without privacy handling guidance.

Install only if users are authorized to process these customer records and recordings. Configure output to a restricted location, avoid broad sharing of raw transcripts and PDFs, redact customer names or phone fragments where possible, and delete exported transcript/report files when no longer needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
This workflow explicitly pulls customer lists, phone tail numbers, AI summaries, and recording-derived transcript text, then consolidates them into markdown, HTML, and PDF outputs, but it provides no explicit warning or handling guidance for sensitive personal data. In this context, the omission increases the chance that operators export, store, share, or further process regulated personal information and conversation content without adequate minimization, access control, or consent checks.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The output artifacts include raw transcript directories and management reports that are likely to embed customer identifiers, behavioral summaries, and quoted speech, yet the skill does not warn users that these deliverables may contain personal data. Because the skill is designed for end-to-end bulk extraction and packaging, this omission materially raises the risk of inadvertent internal over-sharing, insecure retention, and secondary distribution of sensitive customer information.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.