Back to skill

Security audit

Auto Body Collision Repair Kit

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only marketing prompt pack with no code execution, credential use, persistence, or automatic ad launching.

Before using the retargeting ad templates, confirm the shop has an appropriate privacy policy, cookie or pixel disclosure, consent/opt-out handling where required, and platform-compliant audience setup. Treat the legal claims as marketing guidance to verify with current rules or counsel before publication.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The prompt explicitly instructs creation of retargeting ads for website visitors but does not require any privacy disclosure, consent handling, or verification that the necessary tracking notice and permissions are in place. In a marketing skill, this omission can lead users to deploy audience tracking that violates privacy laws or platform policies, especially where cookies/pixels are used for behavioral advertising.

VirusTotal

54/54 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.