Dfw Content Calendar

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent content-calendar generator, but users should be deliberate about whether prompts go to a local model or Anthropic.

Install if you want an LLM-backed marketing calendar generator. Use --demo or --compliance-only for no-API modes, set LLM_BACKEND=local if prompts must stay local, and avoid entering confidential customer data, private campaign strategy, or regulated content unless your policies allow sending it to Anthropic.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill encourages users to provide niche, audience, and marketing copy inputs while requiring an external API key, but it does not clearly warn that those inputs may be transmitted to a third-party model provider. This creates a real privacy and data-handling risk, especially if users include sensitive business plans, customer data, unpublished campaign strategy, or regulated content under the assumption processing is local or self-contained.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The code automatically falls back to Anthropic Haiku and sends user-supplied niche and audience text to a remote third-party service without explicit notice or consent. While this is not code execution, it creates a privacy and data-handling risk because users may assume processing is local by default, especially since the script advertises local MLX as the default path.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal