Back to skill

Security audit

Roadshow Planning

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward Chinese roadshow and fundraising-pitch planning helper with no executable code or hidden authority.

Before installing, expect to share sensitive business-plan, fundraising, team, and financial information when using this skill. Only provide BP file paths or financial data you intend the agent to use for pitch preparation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The skill description contains broad trigger phrases such as planning presentations, summaries, Q&A, and PPT structure, which can overlap with many ordinary user requests outside the intended roadshow/fundraising domain. This can cause accidental invocation, unnecessary context capture, or incorrect routing to a specialized skill that may steer responses toward financing-oriented outputs the user did not request.

Natural-Language Policy Violations

Medium
Confidence
80% confidence
Finding
The skill is written entirely in Chinese and implicitly assumes Chinese-language interaction without documenting language selection or fallback behavior. In multilingual environments, this can lead to unintended language forcing, user confusion, or misinterpretation of financial planning output, especially when the user requested another language.

VirusTotal

54/54 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.