Back to skill

Security audit

Desktop Support

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward career-roadmap API skill, with the main consideration that it sends career profile details and session identifiers to an external service.

Install only if you are comfortable sending career background, skills, goals, timestamps, and any provided session or user identifier to the service operator. Prefer anonymous or minimal identifiers where possible, and avoid including confidential employer details, HR records, or unnecessary personal information.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly collects and transmits session identifiers, timestamps, and an optional userId, which are tracking-related data elements that can be linked to a user or a user session. Because the skill does not disclose privacy implications, retention, sharing, or minimization expectations, it creates a real privacy and data-handling risk, especially when sent to a third-party API.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal