Back to skill

Security audit

Bathroom Remodeling Marketing Kit

Security checks across malware telemetry and agentic risk

Overview

This is a text-only marketing skill with no malware signals, but it claims legal/compliance safety while including ready-to-use outreach that could be misleading or noncompliant.

Install only if you will treat outputs as drafts. Before using any generated copy, remove satisfaction-conditioned review wording, add a real consent-capture process before SMS outreach, replace or verify all license/certification claims, and confirm permit, advertising, FTC/TCPA/RESPA, and contractor rules for your actual jurisdiction.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Intent-Code Divergence

Medium
Confidence
98% confidence
Finding
The file broadly asserts FTC-2023 compliance, but multiple included templates later use conditional phrasing such as 'if you're happy' or 'if we earned it,' which can amount to review gating or sentiment-conditioned solicitation. In a marketing skill specifically designed to operationalize review outreach, this mismatch is dangerous because users may rely on the compliance claim and deploy noncompliant language at scale.

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The prompt states that SMS templates include a PEWC confirmation step, but the actual messages only say PEWC was already confirmed and do not provide any consent-capture or confirmation flow. For a compliance-focused marketing skill, this can mislead users into sending review-request texts without a documented consent mechanism, creating TCPA/marketing-consent exposure.

Intent-Code Divergence

Medium
Confidence
98% confidence
Finding
The skill instructs users to claim use of "ASHI-certified plumbing and electrical subs," but ASHI is not a recognized plumbing or electrical trade credential. This can cause deceptive marketing and misrepresentation to prospects or partners, creating legal, reputational, and compliance risk if users send the outreach as written.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
Several review requests steer dissatisfied customers toward private contact channels with phrasing like 'that's faster than a review,' which can function as soft suppression of negative public feedback even if not explicit gating. In reputation-management content, this creates a heightened risk of deceptive review practices because the skill is directly instructing users how to shape review outcomes.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The scripts repeatedly tie review requests to positive satisfaction cues, despite the document's own claim that requests are unconditional and non-gated. Because the skill's purpose is to generate compliant review solicitation language, these embedded contradictions materially increase the risk that users will deploy prohibited or deceptive outreach.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The prompt is framed as a general marketing skill but embeds Nevada/Clark County-specific legal and compliance requirements from the outset without requiring the user to confirm jurisdiction. That can produce compliance advice and ad copy that is incorrect for other regions, leading users to rely on inapplicable legal representations or omit required local rules.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The checklist hard-codes Clark County and Nevada-specific licensing, insurance, complaint, and permit references as mandatory items, which may be wrong outside that locale. In a compliance-oriented skill, this is especially risky because users may treat the output as authoritative and deploy legally inaccurate ads, outreach, or operational checklists.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.