Back to skill

Security audit

Competitive Analysis

Security checks across malware telemetry and agentic risk

Overview

This is a transparent competitive-research checklist that uses public sources and does not install code, request credentials, or persist in the environment.

Reasonable to install for structured competitive analysis. Be aware it may activate on broad competitor-related questions, and keep research limited to lawful public sources unless you intentionally provide private business context for the analysis.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are broad business-language terms such as "who are my competitors" and "competitive landscape," which can match many ordinary requests and cause the skill to activate outside its intended scope. Over-broad activation can route users into a detailed competitor-analysis workflow unnecessarily, increasing the chance of unintended data collection, poor task routing, or advice being applied in the wrong context.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.