Back to skill

Security audit

private-equity

Security checks across malware telemetry and agentic risk

Overview

This is a coherent private-equity workflow skill, but it can write confidential deal materials to Notion when connected without an explicit consent gate.

Before installing, decide whether this skill should be allowed to use Notion. For confidential transactions, require explicit confirmation before any Notion write, verify the target workspace and permissions, and prefer local Markdown output unless the user intentionally wants shared persistence.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The README states that users can 'say their need' and the system will automatically match a sub-skill, but it does not define clear routing boundaries, exclusion conditions, or confirmation requirements. In a multi-skill agent environment, overly broad activation can cause the private-equity skill to trigger on ambiguous prompts, leading to inappropriate handling of sensitive legal, financial, or investment content and increasing the chance of cross-skill prompt injection or misrouting.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The routing logic explicitly allows activation based on broad 'scenarios' described in the function descriptions rather than narrowly scoped trigger phrases. That increases the chance the skill is invoked for loosely related finance or document-review requests, causing unintended workflow execution, incorrect template loading, or over-collection of user data in contexts the user did not intend.

Vague Triggers

Medium
Confidence
88% confidence
Finding
Several listed triggers are generic phrases such as requests to 'review' terms, calculate returns, or screen projects, which can appear in many unrelated business conversations. In a private-equity skill, this broad matching makes accidental activation more likely and could lead the agent to apply specialized investment workflows to the wrong task or expose users to misleading domain-specific outputs.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill handles potentially highly sensitive deal-screening content, including financials, valuation, governance issues, and founder background, and then describes writing the memo into Notion without any consent, warning, or data-handling guardrails. In a private-equity context, silent persistence to a third-party system can cause confidentiality breaches, unauthorized retention, and downstream overexposure of non-public investment information.

Missing User Warnings

Low
Confidence
92% confidence
Finding
The skill instructs writing investment committee materials to Notion without requiring an explicit user confirmation or warning that highly sensitive deal information may be transmitted to and stored in a third-party service. Because investment memos commonly contain confidential company, financial, legal, and transaction data, silent export to an external connector can create unintended data disclosure, retention, and compliance risks.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill describes sending document-derived review content to Notion without an explicit warning, consent gate, or data-handling notice. Because term sheets, SPA/SHA documents, and diligence materials often contain confidential deal terms and personal or corporate sensitive information, silent transmission to an external service can cause unintended data exposure.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.