Campaign Review

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only campaign review skill with broad business guidance but no code, install hooks, credential use, persistence, or hidden behavior.

Safe to install based on the reviewed artifacts. Use it for campaign reviews and related business planning, but avoid pasting secrets or unnecessary sensitive business data, and have legal, financial, compliance, medical, or high-impact recommendations reviewed by a qualified human expert.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill is framed as broadly applicable to general business operations, strategic decision support, automation, and compliance without clear boundaries, allowed tasks, or disallowed sensitive uses. This can cause overbroad invocation and context oversharing, leading users or downstream agents to apply the skill to inappropriate domains or submit unnecessary sensitive business data.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal