Draco Competitor Analysis

Security checks across malware telemetry and agentic risk

Overview

This is a markdown-only competitor-analysis writing framework with no code execution, credentials, persistence, or hidden data access.

Safe to install for competitor-analysis drafting. Users should make sure their request actually involves competitor or benchmarking analysis, and should verify sources, facts, and business assumptions before relying on the generated recommendations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The invocation guidance is broad enough to capture many ordinary marketing-analysis requests, which can cause the agent to route users into this skill even when they did not specifically ask for competitor-analysis. Overbroad routing increases the chance of scope creep, unnecessary use of competitor framing, and incorrect strategic recommendations based on mismatched task intent.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal