Digital Marketing

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed, instruction-only digital marketing skill with optional consent-based memory and no code, credentials, or automatic external actions.

Reasonable to install if you want a marketing planning assistant. Before enabling continuity, confirm what business context will be saved, avoid storing sensitive strategy unless needed, and require separate approval before publishing content, changing budgets, launching ads, or making regulated claims.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The setup text defines a very broad first-use trigger covering 'ongoing help with digital marketing, growth marketing, launches, funnels, or channel strategy,' which overlaps with many general business conversations. This can cause the skill to activate outside its intended scope, leading to unnecessary memory writes, context steering, or user confusion if the agent invokes specialized behavior when the user did not request it.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The instruction to 'save that activation preference in their main memory so the skill appears when it should' lacks scope limits, duration limits, and confirmation thresholds. If applied loosely, this can create persistent over-activation across future conversations and cause the system to surface this skill in contexts only loosely related to marketing, which is a policy and privacy risk even without obvious malicious intent.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal