Back to skill

Security audit

Startup Problem Finder

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed startup-review assistant with no hidden execution, upload, persistence, or mutation behavior found.

Before installing, treat any uploaded pitch deck, memo, financial table, or founder strategy as sensitive. The skill itself does not add an API client or automatic uploader, but the host agent controls model calls, file processing, search, and retention, so remove credentials, customer lists, bank details, and unnecessary confidential material before use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The default prompt is broadly phrased and can cause the platform to invoke this skill for loosely related startup, fundraising, or investor-discussion queries without clear user intent. That increases the chance of overbroad routing, unintended exposure of user-provided business materials to the skill, and user confusion about when specialized analysis is being applied.

Vague Triggers

Medium
Confidence
93% confidence
Finding
Enabling implicit invocation without narrowing conditions allows the skill to be selected automatically based on broad semantic similarity rather than an explicit user request. In a business-advisory context, this is risky because users may unknowingly have sensitive startup strategy, fundraising, or pitch content routed into the skill when they only intended general discussion.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.