Back to skill

Security audit

TCMS Compliance Reviewer

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed pre-publication compliance reviewer that reads drafts and private review profiles to produce a report without editing the original content.

Installers should be aware that this skill may activate on generic review wording. Use it when you intend a marketing compliance review of a draft and provide only the draft, compliance profile, and knowledge-base references needed for that review.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger list includes very generic terms such as "review" and broad review-related phrases that are likely to appear in many unrelated conversations. This can cause unintended invocation of the skill, routing non-compliance tasks into a workflow that may inspect or process drafts unnecessarily and create confusion, privacy exposure, or workflow misuse.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger list includes very generic activation phrases such as '预审', '审核', '审稿', 'review', and 'fact check', which can easily match ordinary user requests unrelated to this specific compliance-review skill. In an agent environment, overly broad triggers can cause accidental invocation, routing the wrong task to this skill, and potentially exposing drafts or internal marketing content to an unintended processing path.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger list includes broad terms such as 'review', '审核', '预审', and 'fact check' that can match many ordinary user requests outside the intended narrow compliance-review use case. This can cause the skill to activate unexpectedly, pulling the agent into a compliance workflow when the user wanted a general review, creating misrouting, confusion, and possible unintended access to private compliance profiles or draft-handling logic.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.