Back to skill

Security audit

Training Execution

Security checks across malware telemetry and agentic risk

Overview

This skill is a simple training-event tracking template, with expected handling of attendee and score information but no hidden code or automatic access.

Before using it, treat attendee rosters, attendance, and scores as personal data: share outputs only with authorized staff, minimize identifiers in reports, and follow your organization's retention and privacy rules.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly processes attendee rosters, attendance records, and test results, which are personal data and may include sensitive performance information. Because the skill provides operational handling guidance without any privacy notice, data-minimization guidance, access-control expectations, or retention/deletion constraints, it could encourage users to collect, expose, or retain personal information inappropriately.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.