Back to skill

Security audit

Training Partner Mgmt

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward partner-management template that handles sensitive business records, but it does not include code, automation, hidden access, or unrelated behavior.

Before installing, treat this as a business-record handling skill: only provide partner financial, tax, contract, and contact data when you have authority to process it, and add your own rules for redaction, access control, retention, and deletion.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill is explicitly designed to collect and manage sensitive third-party business and personal data, including bank account details, tax information, contracts, invoices, and named contact records, but it provides no privacy notice, handling constraints, minimization guidance, or data-protection safeguards. This increases the likelihood that users or downstream agents will process, store, or expose regulated or confidential information without appropriate consent, retention controls, access restrictions, or redaction.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.