胡田 OPC导师 服务尽调

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only due-diligence skill that discusses sensitive business and customer data but does not execute code or hide behavior.

Install only if you need a structured service-business due diligence framework. Before using it with real company materials, confirm authorization to review CRM, finance, employee, customer, call, chat, or video-monitoring data, and apply legal/privacy review, data minimization, access controls, and retention limits.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The document promotes AI quality-inspection use cases such as video monitoring, voice-call scoring, and chat-record review without any mention of privacy safeguards, consent, data minimization, retention, or legal compliance. In a commercial due-diligence skill for service industries, this omission can normalize intrusive monitoring practices and lead users to deploy surveillance-oriented capabilities in ways that violate privacy obligations or expose sensitive customer and employee data.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal