Back to skill

Security audit

community-building-playbook

Security checks across malware telemetry and agentic risk

Overview

The skill is a non-executable community growth playbook, but it includes cold outreach and personal-data collection guidance without enough consent, privacy, or platform-rule safeguards.

Review and edit the playbook before relying on it operationally. Add explicit rules for opt-in or prior-relationship outreach, platform-policy compliance, rate limits, and human approval before any DMs or public posts. Add a privacy notice and minimize fields in ambassador forms.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
The guidance to 'DM competitors' followers' endorses unsolicited outreach to third parties based on inferred affiliation, which can enable spammy or invasive contact patterns and may violate platform terms. In a reusable agent skill, this is risky because an automated assistant could operationalize the tactic at scale without consent checks or policy guardrails.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The trigger phrase 'any variation of how do I grow my community' is overly broad and can cause the skill to activate for loosely related prompts beyond its intended scope. Overbroad activation increases the chance the agent injects aggressive growth tactics into contexts where they are inappropriate, including policy-sensitive outreach or moderation scenarios.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The launch distribution section recommends direct outreach and posting tactics but omits safeguards around consent, rate limits, anti-spam obligations, subreddit rules, and platform enforcement. In skill form, that omission is dangerous because it normalizes high-risk acquisition behavior and could lead an agent to suggest or automate outreach that harms users, targets, or the operator's accounts.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The ambassador application template requests personally identifiable information, including name, email, location, and social media accounts, but provides no notice about why the data is collected, how it will be used, how long it will be retained, or whether consent is being obtained. In a community-growth skill, this is especially relevant because operators may copy the form verbatim into production workflows, creating privacy compliance and trust risks under laws such as GDPR/CCPA and increasing the chance of over-collection.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.