Back to skill

Security audit

consulting-delivery

Security checks across malware telemetry and agentic risk

Overview

The skill is coherent for creating consulting deliverables, but it may automatically publish sensitive work materials to Notion and grants broad local tool access without clear per-action consent.

Install only if you are comfortable with consulting materials being processed by broad local tools and potentially sent to Notion when a connector is available. For confidential client work, disable Notion publishing or require an explicit pre-publish review of the exact content and destination, and avoid giving the skill access to files or credentials outside the specific engagement materials.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (17)

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
The skill explicitly includes automatic publishing of generated executive summaries and backup pages to Notion, which extends behavior from content drafting into external system actions. In an enterprise setting, this creates a real risk of unintended disclosure, propagation of sensitive business information, or posting to the wrong workspace/page if publication is not explicitly gated and scoped.

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The skill’s core purpose is report generation, but it also introduces an operational side effect: publishing content to Notion. That expands the trust boundary from local content formatting to external data transmission, which can expose sensitive project updates, client information, or internal status details if users are unaware or the connector is misconfigured.

Context-Inappropriate Capability

Medium
Confidence
86% confidence
Finding
Adding WebSearch for industry and policy monitoring exceeds the minimum scope of compiling a weekly status report and can cause the agent to pull in unnecessary external data. This increases the chance of misinformation, irrelevant content injection, or accidental inclusion of unverified third-party information in client-facing reports.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The README states the skill is triggered through natural conversation and will auto-match subskills based on user phrasing, but it does not define clear routing boundaries, confirmation steps, or disambiguation rules. In a multi-skill agent environment, this can cause unintended activation on ordinary business requests, leading to unexpected processing of sensitive project content or execution of the wrong workflow.

Vague Triggers

Medium
Confidence
90% confidence
Finding
Many listed triggers are generic workplace phrases such as '周报', '项目进展', '会议记录', and '市场研究', which are likely to appear in routine user conversation outside deliberate skill invocation. Because this skill handles consulting deliverables that may include confidential business data, trigger collisions increase the risk of accidental activation, unintended context capture, or output generation using sensitive material.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are very broad and include common business requests such as writing reports, summaries, and weekly updates. This can cause the skill to activate in situations the user did not explicitly intend, leading to incorrect routing, unnecessary tool usage, or unintended application of rigid templates.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The routing logic relies on broad keyword and scene matching, including subjective 'highest match' selection, which is prone to misclassification. In a multi-function skill with mandatory template loading and possible file operations, ambiguous routing can push the agent into the wrong workflow and produce unintended outputs.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill permits generating files and writing outputs without clearly warning the user up front that local files may be created or modified. This reduces informed consent and increases the risk of unexpected workspace changes, especially if a user believes the skill will only draft text in-chat.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill enables Shell access even though its documented purpose is consulting deliverable generation, and it does not disclose to users that command execution may occur. Shell capability materially increases risk because a misrouted or poorly constrained workflow could run commands unnecessarily, exposing the environment to unintended side effects.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill advertises automatic publication of benchmarking reports to Notion but does not warn that reports may contain sensitive internal business data, competitive assessments, or client information that would be sent to an external third-party service. In a consulting-delivery context, this increases the risk of unintended data disclosure because users may assume output remains local unless explicitly told otherwise.

Missing User Warnings

Medium
Confidence
98% confidence
Finding
The output section operationalizes automatic posting to Notion and returning a document link, but provides no privacy, confidentiality, or permissions warning despite handling potentially sensitive strategy, financial, and operational benchmarking content. Because this skill is for consulting deliverables, the context makes the issue more dangerous: accidental publication could expose client or internal competitive information to broader audiences through workspace misconfiguration or overbroad sharing.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly states that research reports may be automatically published to Notion, but it does not require an explicit user confirmation or warn that potentially sensitive uploaded materials and generated analysis will be sent to an external third-party service. In a consulting-delivery context, reports often contain confidential client, market, or strategy information, so silent publication materially increases data leakage risk.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The skill hard-requires Chinese output ('所有输出使用中文') without providing a user language choice. This can override user preferences or higher-level application expectations, causing unintended behavior, reduced usability, and possible policy mismatches in multilingual environments. In this consulting-delivery context it is not directly security-critical, but it is still a real prompt-quality/control issue because it constrains output regardless of user need.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill explicitly advertises automatic publication of interview notes to Notion, but the surrounding text does not present a prominent user-facing consent gate, data-classification check, or warning that sensitive material may be transmitted to a third-party service. In this context, the content being handled includes confidential interviews, Chatham House Rule material, possible insider information, and client-sensitive notes, so silent or routine external syncing creates a meaningful risk of unauthorized disclosure, compliance violations, and over-sharing beyond the minimum necessary audience.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill advertises automatic publication to Notion as an enhancement but does not warn that report contents may be transmitted to an external third-party service. In a consulting-delivery context, reports often contain confidential business data, interview notes, internal metrics, or sensitive client strategy, so silent external sharing materially increases data leakage risk.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The output workflow states that if Notion is connected, the complete report will be automatically published, but it omits a clear consent checkpoint or warning about external transmission. Because the generated output may include sensitive commercial, legal, or internal operational information, automatic publishing can cause unintended disclosure without the user's informed approval.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
Automatic publication of weekly reports to Notion lacks an obvious warning about confidentiality, audience scope, and permission risks. Weekly reports often contain sensitive internal project status, customer feedback, delays, staffing issues, or budget details, so silent or under-signaled publication can lead to data leakage into broader workspaces.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.