Back to skill

Security audit

B2b Marketing Playbook

Security checks across malware telemetry and agentic risk

Overview

This appears to be a disclosed B2B marketing and sales playbook, with privacy and compliance cautions users should apply before using outreach or tracking tactics.

Before installing, treat this as business and outreach guidance rather than an automation tool. Use it only with lawful contact lists, appropriate consent or legitimate-basis review, anti-spam compliance, and care around recipient tracking, payment pressure, and escalation tactics. VirusTotal telemetry is clean, and the supplied artifacts do not show hidden execution or credential access.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The manifest and earlier sections describe a playbook for LinkedIn, cold email, webinars, ABM, and marketing metrics. The 'Enterprise Deal Mechanics' section instead provides guidance on contract payment terms, late penalties, withholding features until invoices clear, escalation to CEOs for overdue balances, SOW/SOR change control, and partner economics, which are sales/contract-operations guidance rather than marketing behavior.

Vague Triggers

Medium
Confidence
95% confidence
Finding
This markdown manifest-style section defines triggers such as "B2B marketing," "lead generation," "pipeline," and multilingual equivalents without narrowing context or providing exclusion conditions. These phrases are common in normal business discussions, so the activation scope is ambiguous and may overlap with everyday speech rather than a clearly bounded skill invocation.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
This is a markdown file, so missing user-facing warnings about behaviors that could affect user data or privacy should be flagged. The document instructs users to run cold email sequences, LinkedIn DM outreach, and signal tracking, but provides no caution about lawful consent, data handling, or the impact on recipients and tracked individuals.

Natural-Language Policy Violations

Low
Confidence
78% confidence
Finding
Natural-language policy violations apply to all file types, including markdown. This README is entirely in Japanese and does not indicate that the locale is optional, user-selected, or justified as region-specific, which can conflict with a policy requiring language/locale choice or explicit justification.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.