Pickfu Market Research

Security checks across malware telemetry and agentic risk

Overview

This is a coherent PickFu survey-integration skill, with real account and privacy implications that are disclosed and mostly gated by user confirmation.

Install this only if you intend to let an agent operate your PickFu account for survey workflows. Review the survey design, audience, sample size, uploaded media, and cost before approving publish or respondent-add actions. Avoid submitting secrets, credentials, regulated personal data, customer data, or confidential unreleased assets unless you are comfortable sharing them with PickFu and survey respondents.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill description is broad and highly user-invocable, covering many common market-research tasks without clear activation boundaries. In an agent environment, this can cause over-triggering on loosely related requests, leading the agent to invoke external survey-generation, media-generation, or account-billing workflows when the user did not explicitly intend to use PickFu.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal