Back to skill

Security audit

OEM/ODM RFQ Assistant

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward RFQ drafting assistant with a local helper script, and its handling of buyer inquiry text fits its stated purpose.

Before installing, confirm you are allowed to process buyer inquiries in your AI environment. Redact unnecessary personal data, confidential drawings, customer identifiers, pricing targets, and proprietary specifications when possible. Replace the placeholder company facts and examples with verified company information before sending drafts externally.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The README explicitly encourages users to paste buyer emails into the skill but does not warn about privacy, confidentiality, or data-handling risks. In a B2B RFQ context, emails often contain personal data, pricing expectations, drawings, and business-sensitive information, so users may disclose sensitive content to the agent or surrounding tooling without realizing the exposure.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.