Back to skill

Security audit

AI Market Research

Security checks across malware telemetry and agentic risk

Overview

This market-research skill appears purpose-aligned and not malicious, but it needs review because it promotes automatic persistence and external report delivery without enough user controls or privacy disclosure.

Install only if you are comfortable with market-research topics, reports, and summaries being saved locally and possibly in agentmemory. Do not enable scheduled WeChat/channel delivery for confidential work unless you verify the destination, add a review step, and understand exactly what will be sent. Treat this version as early-stage because several advertised integrations appear simulated or not yet implemented.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The README markets the skill as already integrating crawl4ai, trendradar, and product-research, while the roadmap states that real MCP calls and deeper integrations are not yet implemented. This is a security-relevant integrity issue because operators may enable the skill with incorrect assumptions about what code paths, data flows, and external services are actually in use, reducing informed consent and safe deployment review.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The README promotes scheduled market research with automatic delivery to WeChat without prominently disclosing outbound network collection, third-party content retrieval, and external publication risks. In an agent skill context, this can lead to unreviewed data exfiltration, privacy issues, or unintended sharing of collected or generated content to external channels.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The configuration includes an `auto_push_to_channel` option that can publish generated reports to an external channel without any warning, consent flow, or guardrails described in the requirements. In a market-research skill that aggregates external data and may include sensitive internal analysis, silent outbound publication increases the risk of accidental data leakage and unauthorized distribution.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill states that research findings are automatically written to agent memory/vector storage without clearly warning users about retention, indexing, or possible storage of sensitive business data. In a market-research context, collected material may include proprietary topics, internal plans, or personal data from source content, making silent persistence risky.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill documents external crawling, trend monitoring across platforms, and optional WeChat pushing, but does not clearly warn that user queries, source URLs, scraped data, or report contents may be transmitted to third-party services. This can expose confidential research topics or collected content outside the local environment without informed consent.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.