Back to skill

Security audit

Saas Growth Playbook

Security checks across malware telemetry and agentic risk

Overview

This is a non-executable SaaS growth advice skill with one privacy caveat around session recordings, but no hidden code or automatic data collection.

Installers should treat this as business advice, not an implementation-ready compliance plan. If following the session-recording recommendation, use clear user notice and consent where required, mask sensitive fields, limit retention, restrict access, and verify the approach against applicable privacy obligations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The playbook explicitly recommends using session recordings for churn analysis but provides no guidance on user notice, consent, data minimization, or handling of potentially sensitive captured data. In a SaaS growth context, this can normalize privacy-invasive monitoring and lead operators to collect user interactions in ways that violate privacy expectations, contractual commitments, or regulatory requirements.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The document recommends using session recordings as part of churn analysis but provides no warning about privacy implications, consent requirements, or the need to avoid capturing sensitive data. In a SaaS growth playbook, this can normalize deploying behavioral tracking without proper notice, minimization, or compliance controls, creating privacy and regulatory risk.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.