Startup 0 to 1 Workflow

Security checks across malware telemetry and agentic risk

Overview

This is a startup planning workflow with a simple local script and no evidence of credential access, data exfiltration, persistence, or destructive behavior.

Safe to install as a startup planning aid. Be aware it may activate on broad startup or founder discussions, and review any separate skills it recommends before giving them sensitive business, fundraising, or market research data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger list contains very broad terms such as "startup", "founder", and entrepreneurship-related Chinese keywords that are likely to appear in ordinary discussion. This can cause unintended invocation of the skill in contexts where the user did not request a full startup workflow, leading to context hijacking, irrelevant responses, or unexpected chaining into other skills.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal