Back to skill

Security audit

Opc Live Compliance

Security checks across malware telemetry and agentic risk

Overview

This skill is framed as livestream compliance guidance, but parts of it can steer an agent toward deceptive or manipulative sales scripts.

Before installing, review and remove the conflicting sales-script sections or constrain the skill to verified claims only. Do not let it generate stock counts, expert credentials, audience behavior, social proof, health/body-effect claims, or urgency language unless those facts are true, documented, and approved for the platform.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Intent-Code Divergence

High
Confidence
97% confidence
Finding
The skill starts as a compliance guide, but later sections reintroduce exactly the kinds of manipulative and potentially non-compliant livestream tactics it earlier forbids, such as scarcity pressure, authority claims, social-proof manufacturing, and conversion-driving scripts. In a skill that may be used operationally by an agent to generate live sales content, this contradiction can cause the agent to produce deceptive or policy-violating output despite the earlier compliance framing.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.