CMO Helper

Security checks across malware telemetry and agentic risk

Overview

This is a chat-only advertising planning skill with no code execution, credential access, persistence, or hidden data movement.

Install this if you want help structuring ad-channel planning and executive growth reports. Avoid entering confidential business numbers unless you are comfortable discussing them in chat, and treat forecasts as planning scenarios rather than guaranteed financial outcomes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger list is broad enough to match generic business and marketing requests such as 'growth', 'strategy', 'budget', and 'report', which can cause the skill to activate outside its intended niche. Over-broad invocation increases the chance of wrong-skill routing, lower-quality responses, and unintended handling of user queries with financial-planning framing the skill is not actually equipped to validate safely.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal