customer-response-generator

Security checks across malware telemetry and agentic risk

Overview

This is a simple customer-support writing helper with no executable code or system access, though users should avoid pasting unnecessary sensitive customer details.

Safe to install as a writing aid. Before using it, redact unnecessary personal data, payment details, account identifiers, tracking numbers, and other sensitive customer information unless needed for the reply, and review generated responses before sending.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The usage instructions explicitly encourage users to paste customer messages, order details, and policy context without any warning to minimize or redact personal, financial, or account data. In a customer-support context, those inputs commonly contain PII and order identifiers, so the absence of data-handling guidance creates a realistic privacy and compliance risk through oversharing.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal