GenAI CyberSec

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed API/documentation skill for generating cybersecurity roadmaps, but users should treat the submitted organization and contact details as sensitive.

Install/use only if you are comfortable sending organizational cybersecurity posture, budget, concerns, contact details, and user/session metadata to this provider. Avoid entering credentials, confidential incident details, regulated data, or internal architecture secrets unless you have separately verified the provider's privacy and security terms.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly collects identifiable and potentially sensitive organizational data such as organization name, government affiliation, contact email, user ID, session IDs, timestamps, role, and department, but provides no privacy notice, data minimization guidance, retention policy, or handling constraints. In a cybersecurity-planning context, this metadata can reveal sensitive operational details and create unnecessary exposure if logged, retained, shared with third parties, or breached.

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The schema explicitly accepts multiple identifiers and contact data, including x-session-id, x-user-id, sessionId, userId, and additionalInfo.email, but provides no indication of data minimization, purpose limitation, retention, or transport/security requirements. In a skill that processes organizational cybersecurity assessments, these fields can link sensitive posture information to identifiable users or organizations, increasing privacy and correlation risk if logged, stored, or transmitted insecurely.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal