Back to skill

Security audit

Cb Global Content Strategy

Security checks across malware telemetry and agentic risk

Overview

This is a prompt-only marketing localization skill with no code, credentials, or hidden system access requested.

Reasonable to install for content localization planning. Treat its market, language, and cultural recommendations as draft strategy, and use local legal/cultural review before publishing sensitive or regulated content.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Low
Confidence
82% confidence
Finding
The getting-started trigger guidance uses a very broad pattern: 'Build a content strategy for [brand] in [market]' and 'Tell me your brand and target market'. This does not define clear boundaries for when the skill should or should not activate, so it may match ordinary content-planning requests outside the intended global-local localization workflow.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The example expected output instructs that localized content should 'use English' and specifically references US/Canada presentation norms, which imposes a language choice rather than offering it as an option. This is a natural-language locale policy issue because it forces a specific language for the user scenario without documenting user choice or a justified regional constraint.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.