startups-page-generator

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only marketing page helper with no code execution, install hooks, credential handling, persistence, or hidden behavior.

Safe for normal use as a marketing/page-generation helper. Before installing, review any `.claude/project-context.md` or `.cursor/project-context.md` files because this skill may use them to shape generated copy; avoid keeping secrets or internal-only information in those files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The invocation description is broad enough to match common phrases like "special pricing" or "for students," which can cause this skill to be selected outside its intended scope. Misrouting is not a direct code-execution issue, but it can lead to incorrect guidance, context confusion, and inappropriate handling of requests that should go to a more specific skill such as education-program or pricing-page-generator.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal