privacy-page-generator

Security checks across malware telemetry and agentic risk

Overview

This is a low-risk drafting aid for privacy-policy pages, with no evidence of code execution, data access, persistence, or hidden behavior.

Install this if you want help drafting or structuring a privacy policy or privacy notice. Treat its output as a starting point: confirm that it matches your actual data practices, cookies, vendors, retention periods, and applicable laws, and have a qualified reviewer check it before publishing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The invocation rule is overly broad because it triggers on many generic privacy-related terms such as "personal data," "data privacy," and "GDPR compliance," which can appear in contexts where the user is not actually asking to create or edit a privacy policy page. This can cause unintended skill activation, leading the agent to produce legal-page guidance when a narrower privacy, security, or compliance response was intended.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal