audience analysis

Security checks across malware telemetry and agentic risk

Overview

This is a simple audience analytics skill that discloses its data inputs and API endpoint, with only a mild caution about broad trigger wording and sensitive behavior data.

Use this skill only when you intend to analyze audience or content performance data. Share the minimum necessary behavior data, preferably anonymized or aggregated, and confirm that the configured analysis API is appropriate for any personal or business-sensitive information.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger conditions are broad enough that the skill could be invoked for loosely related requests, especially the generic '任务涉及 audience/analyze 时' phrasing. In an agent system, ambiguous routing can expose user data to the wrong skill, cause unintended API calls, or produce analysis results when the user did not explicitly request audience profiling.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal