Back to skill

Security audit

Part 2 Notice Assessment

Security checks across malware telemetry and agentic risk

Overview

The skill is a coherent public-document compliance checker, but users should keep it limited to public notices or trusted public URLs.

Install only if you want a legal/compliance drafting aid for public Part 2 notices. Prefer pasted notice text or trusted public http/https URLs, and treat outputs as document-review findings rather than legal conclusions about an organization's real operations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Context-Inappropriate Capability

Medium
Confidence
89% confidence
Finding
The skill explicitly instructs the agent to use Bash and network retrieval to fetch live website content. That expands the trust boundary from a pasted document to arbitrary remote content and can expose the agent to SSRF-style access, unexpected internal URLs, oversized or hostile responses, and analysis based on attacker-controlled pages.

Intent-Code Divergence

High
Confidence
93% confidence
Finding
The skill says it assesses only the posted notice, but the applicability gate later tells the agent to assess an entity's broader 'actual Part 2 posture' for non-program entities. That scope expansion can induce the agent to make claims beyond the provided public document, increasing the risk of unsupported compliance judgments and disclosure or processing of unrelated sensitive policy material.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.