podcast-marketing

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only podcast marketing guide with no code, installs, credentials, persistence, or account authority.

Safe to install for podcast marketing help. Review your .claude/project-context.md or .cursor/project-context.md files first if present, since the skill may use them to tailor advice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The manifest description contains very broad trigger phrases such as generic mentions of "podcast," which can cause the skill to activate in contexts where the user did not actually request podcast marketing help. Over-broad activation increases the chance of irrelevant routing, context leakage into the wrong workflow, and accidental execution of instructions that are not the best fit for the user's intent.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal