Security Posture Maturity

Security checks across malware telemetry and agentic risk

Overview

The skill appears purpose-aligned, but it sends identifiable assessment metadata to a third-party API without enough privacy and retention disclosure.

Review what assessment details are sent to the third-party API before installing. Avoid submitting customer-identifying or sensitive internal security information unless the API provider’s privacy, retention, and access-control terms are acceptable.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill documentation explicitly includes transmission of `sessionId`, `userId`, and timestamped assessment data to a third-party API without any statement about data minimization, retention, access controls, or privacy handling. Even if the fields are not highly sensitive by themselves, they can enable correlation of user activity and organizational assessment records, which is risky in a security-assessment context where metadata may reveal internal posture or customer identity.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal