Back to skill

Security audit

Feedback Roadmap

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow for prioritizing ecommerce feedback, with a privacy handling gap but no hidden execution, persistence, or exfiltration behavior.

Before installing or using this skill, confirm you are allowed to process the customer feedback sources involved. Redact or pseudonymize names, emails, order numbers, addresses, and other identifiers where possible, and avoid carrying unnecessary personal details into the final roadmap or shared verbatim quotes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
This markdown skill explicitly instructs users to synthesize customer feedback from sources that commonly contain personal or sensitive information, including support transcripts and social DMs. The description explains the analysis workflow but does not warn about privacy, consent, redaction, or careful handling of customer data.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
This step directs users to pull raw feedback from reviews, surveys, support chat/email transcripts, return reasons, and social DMs/comments into a normalized table. Because these sources can include personal data, order details, and sensitive free-text content, the skill should include an explicit warning about redaction, least-necessary data collection, and compliance with privacy requirements.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.