Back to skill

Security audit

Training Satisfaction

Security checks across malware telemetry and agentic risk

Overview

This skill is a survey-management template that handles trainee contact and feedback data in a disclosed, purpose-aligned way, though users should add privacy controls before real deployment.

Before using this with real trainees, configure it so only necessary contact data is collected, survey answers are anonymous or pseudonymous where possible, reports are shared in aggregate by default, and retention, deletion, access-control, and consent rules are documented.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill explicitly uses learner names, contact details, departments, and survey response data for distribution, collection, and tracking, but provides no privacy, consent, minimization, retention, or access-control guidance. This creates a real privacy and compliance risk because operators may process personally identifiable information and potentially sensitive feedback without safeguards, increasing the chance of unauthorized disclosure, misuse, or noncompliant handling.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.