Back to skill

Security audit

AIEO monitoring

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent AIEO brand-monitoring tool, but its reports and screenshots can contain sensitive business or account information.

Install only if you intend to run AIEO brand monitoring. Before use, confirm you are authorized to access the analytics, CRM, and logged-in AI-platform accounts involved; keep monitoring/ private, redact sensitive screenshots or responses, and delete reports when no longer needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill instructs collection of traffic, conversion, and platform testing data, which can include sensitive analytics or business performance information, but it does not require user notice, consent, or data-minimization guidance. In practice, this increases the risk of unauthorized access, over-collection, or mishandling of potentially confidential or personal data during monitoring workflows.

Missing User Warnings

Low
Confidence
88% confidence
Finding
The skill persistently writes monitoring reports and screenshots to local directories without clearly warning that potentially sensitive brand, platform-response, or analytics-derived content will be stored on disk. This can expose confidential data to later users, other tools, or accidental inclusion in version control if storage behavior is not made explicit.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The guide instructs operators to capture screenshots and record AI responses across logged-in platforms, but it provides no guidance to avoid collecting visible account information, chat history, personal data, or other sensitive content. In this monitoring context, repeated automated captures increase the likelihood of storing sensitive data in the monitoring directory and reports, creating a privacy and data-handling risk.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.