Back to skill

Security audit

gingiris-kol-outreach

Security checks across malware telemetry and agentic risk

Overview

This is a marketing playbook, but it gives agents and users workflows involving sensitive creator contact, payment, tracking, and bulk outreach data without enough privacy or anti-spam guardrails.

Install only if you are comfortable using it as a human-reviewed marketing reference. Do not let an agent automatically send outreach, upload contact CSVs, collect bank details, or post across groups without your approval, a lawful contact source, opt-out handling, secure payment workflows, and compliance review for the platforms and jurisdictions involved.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The README explicitly promotes using AI agents to generate outreach emails, build KOL lists, create tracking structures, and calculate ROI, but it provides no guidance on handling personal contact data, consent, scraping legality, or secure treatment of analytics/UTM data. In a marketing automation context, that omission can lead users to process influencer PII or behavioral data through third-party agents and tools in ways that violate privacy expectations, platform rules, or internal data-governance requirements.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger list uses very broad, generic marketing phrases such as 'influencer marketing', 'creator partnership', and 'content creator outreach', which can easily appear in ordinary user discussion. That increases the chance the skill is invoked when the user did not intend to activate it, causing irrelevant guidance to override or distract from the primary task.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
Declaring Chinese as the default language without explicit user opt-in can cause the skill to respond in a language the user did not request. This can confuse users, reduce transparency, and in some cases lead to misinterpretation of business or compliance-sensitive outreach guidance.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The SOP instructs operators to collect highly sensitive banking details such as account numbers, SWIFT codes, routing numbers, and addresses, but provides no guidance on minimization, secure transmission, retention, access control, or deletion. In a marketing/outreach skill, this creates unnecessary exposure of financial data and raises fraud, privacy, and compliance risks if users store or share the information insecurely.

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The SOP recommends importing CSVs containing personal contact data for bulk outreach without discussing consent, lawful basis, source validation, unsubscribe handling, or jurisdictional privacy requirements. That can facilitate unsolicited marketing and unsafe handling of personal data, especially when paired with third-party outreach tools.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The SOP advises matching people across platforms and contacting them via LinkedIn using identities found from Twitter, without warning about privacy expectations, platform terms, or harassment/spam risks. Cross-platform identity correlation increases the intrusiveness of outreach and can enable unwanted tracking or targeting of individuals.

Missing User Warnings

Low
Confidence
78% confidence
Finding
The SOP encourages posting into 30-40 groups per day and broad media seeding without noting community rules, anti-spam restrictions, or consent requirements. In practice this can drive users toward spammy promotion patterns that trigger bans, complaints, or reputational damage.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.