It Risk Assessment Tool

Security checks across malware telemetry and agentic risk

Overview

The skill appears to perform a disclosed security-maturity assessment workflow, with the main caution that it may send sensitive organizational posture details to an external service.

Before installing, treat anything entered into this skill as potentially sent to ToolWeb. Avoid including secrets, exact internal hostnames, customer data, unreleased incidents, or highly specific vulnerabilities unless you are comfortable sharing them with that service and its retention practices.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs the agent to collect detailed organizational security-control maturity data and send it to a third-party API, but it does not require an explicit user warning or consent before transmission. Because this data describes internal security posture and gaps, sending it externally can expose sensitive operational details and create privacy, confidentiality, and supply-chain risk.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal