Back to skill

Security audit

Air Duct Cleaning Iaq Kit

Security checks across malware telemetry and agentic risk

Overview

This is a prompt-only marketing kit, but its compliance claims and declared financial-capability metadata do not fully match the actual templates.

Install only if you will manually review outputs before publishing or sending them. Treat legal, FTC/TCPA, medical-adjacent, and licensing claims as draft copy, not legal clearance; remove satisfaction-gated review requests, verify local licensing rules outside Nevada, and ignore or re-check the financial-authority capability tags unless the publisher explains why they are needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Intent-Code Divergence

Medium
Confidence
98% confidence
Finding
This is a true compliance flaw: the SMS says 'If you're happy, a Google review helps us a lot,' which conditions the review ask on a positive experience despite the prompt explicitly banning selective review requests. In a reputation-management skill, that inconsistency can cause users to generate review-solicitation workflows that suppress neutral or negative feedback, creating FTC endorsement risk and misleading platform reputational signals.

Intent-Code Divergence

Medium
Confidence
89% confidence
Finding
This is a real contradiction in compliance guidance. The template says there must be no FTC-prohibited review incentives, yet it also instructs offering a referral discount; even though it says the discount is to the agent and not the buyer for a review, the overlap between referral compensation and reputation-generation content creates ambiguity that can lead users to implement incentives tied directly or indirectly to endorsements or referrals.

Intent-Code Divergence

Medium
Confidence
96% confidence
Finding
The file claims the ad copy is already 'pre-cleared' for multiple legal and regulatory regimes, which may cause users or downstream agents to trust and publish it without independent review. That is dangerous because the same template contains statements elsewhere that appear inconsistent with its own blocking rules, creating a false sense of compliance and increasing the chance of unlawful or deceptive advertising.

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
Although the prompt says health outcome claims are blocked, it includes copy such as 'Post-COVID IAQ Documentation' and 'Physician-Referral Friendly,' which can imply medically relevant benefits or clinical appropriateness. In an ads-generation skill for consumer services, such suggestions are especially risky because users may deploy them in regulated marketing contexts, leading to deceptive health-adjacent claims and compliance exposure.

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
The prompt hardcodes Nevada-specific licensing and legal requirements (for example, NRS 624 and C-21 references) without confirming that the user's business operates in Nevada. This can mislead users in other jurisdictions into relying on irrelevant or incomplete legal guidance, producing noncompliant ads or omissions in local licensing disclosures.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.