customer-stories-page-generator

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a low-risk marketing/content helper, with only a minor risk that broad trigger phrases could activate it for adjacent writing tasks.

Before installing, be aware that it may be invoked for general marketing-writing requests because its trigger language is broad. Use it when you want help creating page or proof-oriented marketing content, and choose a more specific skill if you need unrelated website, landing-page, or testimonial work.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill declares very broad invocation phrases such as "case study," "testimonials page," and other common marketing terms without defining strong exclusion boundaries. In an agentic environment, this can cause the skill to activate for loosely related requests, leading to inappropriate file reads, irrelevant workflow takeover, or accidental use of the wrong skill in ways that may expose project context or distort outputs.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal