Brand Voice Profile

Security checks across malware telemetry and agentic risk

Overview

This skill appears to help create local brand-voice profiles, with privacy and input-scoping cautions but no evidence of hidden, destructive, or exfiltrating behavior.

Install only if you are comfortable with the agent storing brand voice data on disk. Use it with writing samples, posts, or URLs you are authorized to analyze, avoid sensitive client material unless needed, and use simple profile names without path characters.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
89% confidence
Finding
The skill instructs the agent to create and maintain `brand-voice/profile.json`, which stores potentially sensitive user-authored preferences, examples, and writing patterns, but it does not tell the user that this information will be persisted locally. While this is not overtly malicious, undisclosed storage can create privacy and data-handling risks, especially if authentic writing samples or client-specific voice profiles are later reused, exposed, or synced by other tools.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal