Back to skill

Security audit

Ai Automation Agency Kit

Security checks across malware telemetry and agentic risk

Overview

This appears to be an instruction-only delivery fulfillment playbook with a privacy caution around how it discusses access and credentials.

Install only if you are comfortable using it as a fulfillment planning guide. When it asks about accounts or credentials, provide roles, systems, owners, and access status only; do not paste passwords, API keys, session tokens, recovery codes, or full credential values into chat.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The prompt explicitly instructs gathering information about systems touched, who has admin access, and discussing accounts and credentials, but provides no warning to avoid sharing secrets in-chat or to use secure channels and least-privilege access. In an LLM skill context, this can cause users to paste sensitive credentials or overshare privileged access details into prompts, increasing the risk of accidental exposure, retention, or downstream misuse.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.