Back to skill

Security audit

Smart Venue Map

Security checks across malware telemetry and agentic risk

Overview

This skill builds an offline venue map and its sensitive analytics handling is disclosed, local, and tied to the stated purpose.

Install only if you are comfortable processing venue camera analytics locally. Use lawful, consented, minimized data where possible, and avoid sharing the generated HTML unless the embedded analytics are safe for recipients to see.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Context-Inappropriate Capability

Medium
Confidence
96% confidence
Finding
The script ingests and aggregates demographic camera-analytics fields such as gender, age group, and eyewear, then exports them into dash_data.json for downstream use. That exceeds a narrow 'offline IMDF indoor venue map' purpose and creates unnecessary processing of sensitive or privacy-invasive attributes, increasing compliance, misuse, and surveillance risk even without an obvious exfiltration path.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.