Ransomware Preventer

Security checks across malware telemetry and agentic risk

Overview

This skill describes a simple API for generating ransomware defense recommendations, with sensitive but disclosed organizational data submission.

Safe to install as an API-description skill, but treat any submitted assessment data as sensitive. Avoid sending secrets, internal hostnames, IP addresses, exact inventories, or stable personal identifiers unless necessary, and verify the provider's privacy, retention, and access-control practices before using it with real organizational data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly describes collecting and transmitting detailed organizational assessment data along with session identifiers, timestamps, and optional user identifiers, but provides no privacy notice, retention limits, access controls, or data-handling constraints. In a security-focused product, this is particularly sensitive because the submitted systems, tools, posture, and industry data could help an attacker profile the organization's defenses if mishandled or exposed.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal