First Customers

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only sales coaching skill with broad but disclosed triggers and no code, credential use, persistence, or hidden data access.

Before installing, know that this skill may steer broad sales discussions toward an early-founder, one-to-one outreach playbook. Review any generated contact lists or outreach messages yourself for privacy, consent, and anti-spam compliance.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The read_when condition '用户有了产品但没有客户' and similar phrasing are broad enough to match many ordinary business or marketing discussions, causing the skill to activate outside its intended narrow use case. Over-broad routing can lead to irrelevant guidance being injected into conversations and reduce reliability of agent behavior, though it does not directly create code-execution or data-exfiltration risk.

Vague Triggers

Medium
Confidence
91% confidence
Finding
Generic trigger keywords such as '找客户' and '怎么销售' are common in everyday conversation and can cause accidental invocation of this skill in unrelated contexts. This creates prompt-routing ambiguity and may override a better-matched skill or baseline assistant behavior, producing inappropriate or low-quality responses.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal