Back to skill

Security audit

AI Tooling Inventory

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed healthcare compliance interview and artifact-review workflow for finding AI tools, with sensitive self-inspection steps that are purpose-aligned and bounded.

Before using this skill, tell respondents to share only tool names, access categories, and high-level findings rather than passwords, tokens, patient data, email contents, or screenshots. Treat the own-account checks as a sample, not a tenant-wide audit, and use any Tier 2 exports only as an explicit follow-up pass with appropriate administrative approval.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The walk-through directs respondents to inspect live account portals, inbox contents, and browser extension permissions during an interview session, which can expose sensitive operational details such as authorized third-party apps, email-derived tool usage, and extension access scopes. In this skill’s context, the risk is elevated because the exercise is explicitly aimed at discovering shadow AI tooling, so it is likely to surface security-relevant account and access information without guardrails on minimization, redaction, or how the interviewer should handle what is revealed.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.