Back to skill

Security audit

Training Community

Security checks across malware telemetry and agentic risk

Overview

This skill is a non-executable training community operations template, but users should handle learner roster, referral, participation, and spending data with privacy controls.

Before installing, confirm that your organization is allowed to use learner roster, purchase, referral, and participation data for community operations. Limit fields to what is necessary, restrict access to reports, avoid exposing full identities in routine summaries, and define deletion or retention rules.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly processes learner rosters and tracks participation, referrals, and cumulative spending, which are personal and behavioral data points. Because it provides operational guidance without any privacy notice, data minimization, consent, retention, or access-control safeguards, it can enable unauthorized profiling or noncompliant handling of personal data.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.