GTM Account Research

Security checks across malware telemetry and agentic risk

Overview

This is a markdown-only sales account research skill that uses public web research and does not request code execution, credentials, persistence, or local data access.

Install this if you want a reusable workflow for public GTM account research. Use it intentionally for named companies, verify sources before outreach, and handle named-person details, LinkedIn links, and inferred pain points according to privacy, anti-spam, and workplace policies.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger condition includes a broad phrase about preparing for a meeting with a named account, which can cause the skill to activate in contexts where the user did not explicitly request account research. That ambiguity can lead to unintended web research, disclosure of internal meeting context to external search tools, or the generation of outreach-oriented profiling without clear user intent.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal