Back to skill

Security audit

TCMS Performance Analyst

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed monthly marketing-performance reporting helper that reads specified project data and writes a report, with some routing and data-quality caveats but no hidden execution or destructive behavior.

Install only if you want an agent to analyze internal marketing content, calendars, product maps, channel metrics, and knowledge-base status. Use explicit TCMS/project wording when invoking it, and avoid relying on product-line coverage if the private product map is missing because the fallback can misclassify products from titles.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The skill’s Hard Rules require product-line analysis to use the private product map and forbid inference from titles, but the Failure Handling section allows title-based inference when the product map is missing. This contradiction can cause the agent to fall back to a less reliable and potentially privacy- or integrity-impacting method, producing incorrect product attribution and misleading monthly recommendations while appearing compliant.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger list includes broad, common phrases such as 'monthly report', 'content review', and 'performance analysis', which can match ordinary user requests outside the intended scope. In an agent environment, this can cause the wrong skill to activate, leading to confused routing, unintended access to project data, or generation of analysis in contexts where this skill was not meant to run.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.