AI Tech Intelligence Briefing

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a local daily briefing generator with limited file output and no evidence of hidden data collection.

Install only if you are comfortable with a broad natural-language trigger creating local briefing files in the configured output directory. The documentation advertises live news fetching, but the reviewed runtime currently uses built-in demo content; also use date-like values for fetch commands to avoid reading unintended local markdown files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrase "daily briefing" is generic and likely to overlap with common user requests for summaries or news digests, which increases the chance this skill activates when the user did not specifically intend to invoke it. Because the skill performs network reads and writes output files, accidental activation could cause unintended external requests or content generation even if the package metadata claims limited scope.

VirusTotal

58/58 vendors flagged this skill as clean.

View on VirusTotal