Back to skill

Security audit

Case Study Generator

Security checks across malware telemetry and agentic risk

Overview

This is a prompt-only case study writing skill with no executable code or hidden system access, but users should handle customer details and AI-assisted client work transparently.

Before installing or using this skill, treat it as a drafting aid only: verify all metrics, do not publish invented quotes as real, get written customer approval for names, titles, companies, logos, testimonials, and case-study claims, handle customer contacts as confidential information, disclose AI assistance when contracts or client expectations require it, and ensure outreach complies with applicable privacy and anti-spam rules.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The line explicitly advises service providers to hide AI usage from clients, which promotes deceptive business practices and removes informed consent from the customer relationship. In a marketplace skill, this is risky because it can facilitate fraud, misrepresentation, and contractual or reputational harm for users who follow the guidance.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill explicitly asks users to provide a named customer contact, which is personally identifiable information, but gives no guidance on consent, minimization, or safe handling. In a marketing content workflow, this can lead users to paste real client data into an LLM or shared artifact without authorization, creating privacy, confidentiality, and contractual compliance risk.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The prompt explicitly instructs the model to generate cold/warm outreach email snippets using case study details, named customers, and prospect problem mirroring, but provides no guardrails around lawful basis, consent, privacy, or approved use of customer/prospect information. In a business workflow, this can normalize privacy-invasive or non-compliant outreach and encourage misuse of customer names, quotes, or sensitive commercial details in sales sequences.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.