Back to skill

Security audit

my-ai-skill

Security checks across malware telemetry and agentic risk

Overview

This is a simple symptom-organizing prompt with no executable code or external access, though users should be cautious about sharing health details.

Install only if you want help organizing health conversations. Health information can be sensitive, so share the minimum needed, avoid unnecessary identifying details, and do not use this skill for emergencies, diagnosis, or treatment decisions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
This skill solicits and structures symptom details, medications, existing conditions, and other health-related context, which are sensitive medical data. The skill description and intake flow do not warn users that they may be sharing sensitive information or advise minimizing personal identifiers, increasing the risk of oversharing, inappropriate retention, or downstream privacy exposure.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.