Back to skill

Security audit

Kol Outreach

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only outreach template skill with no hidden execution, data access, persistence, or credential handling.

Use this as a template library, not an automated sending system. Before applying the outreach advice, users should follow anti-spam laws, platform rules, recipient-consent expectations, and avoid deceptive or mass unsolicited outreach.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
This markdown file describes DM and cold-email outreach workflows, including follow-up cadence and deliverability setup, but does not include any warning that these actions may implicate anti-spam rules, platform terms, or recipient consent expectations. For markdown files, SQP-2 applies when descriptions omit warnings about behaviors that could affect privacy or system integrity; unsolicited outreach to individuals can affect recipient privacy and account safety.

Natural-Language Policy Violations

Low
Confidence
95% confidence
Finding
The file content is fully Korean-language instructional text and does not indicate that the user can choose another language or that the skill is intentionally limited to Korean-speaking users. Under SQP-3, forcing a specific language without user opt-in is a natural-language policy concern unless clearly justified as region-specific.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.