Reports Creator

Security checks across malware telemetry and agentic risk

Overview

This skill is a local report generator whose sensitive data use is expected and disclosed, with no evidence of hidden execution, exfiltration, or destructive behavior.

Install only if you are comfortable with reports summarizing logs, databases, memory notes, and system metrics. Before enabling scheduled reports, restrict input paths, redact secrets or personal data, protect the reports directory, and review any report-generation scripts if they are added later.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill explicitly states it generates reports from logs, databases, and system metrics, but it does not warn users that these sources may contain sensitive operational or personal data that will be aggregated into report files. This creates a real risk of unintended disclosure because aggregation often increases sensitivity and persistence of data, especially when written to a shared reports/ directory or distributed further.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal