News Brief Automation

Security checks across malware telemetry and agentic risk

Overview

This is a Markdown-only skill for setting up recurring news digests, with disclosed workspace report writing and summary delivery.

Install this if you want agents to create recurring news-digest prompt files and Markdown reports in your workspace. Before use, confirm the sources, cadence, save paths, and delivery target, and avoid putting private credentials or sensitive links into the generated automation prompts.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The manifest description is broad enough to match ordinary user requests about checking news, summaries, trend briefings, or reusable reporting workflows, which can cause the skill to activate outside narrowly intended scenarios. Overly permissive activation increases the chance of unintended tool use, file creation, or automation changes in response to general informational requests, especially because this skill writes cron prompts and report files in the workspace.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal