Back to skill

Security audit

Advisor Board Pro

Security checks across malware telemetry and agentic risk

Overview

This skill is coherent as a business-advisor tool, but it advertises team sharing, report export, web research, and automatic record sync without clear controls for sensitive business data.

Review how prompts, reports, exported files, shared history, team access, and migrated records are stored and controlled before installing. Avoid entering confidential strategy, investment, customer, or operational data until the publisher explains retention, access permissions, export locations, and how to disable sharing or automatic sync.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill advertises deep web retrieval, team collaboration, report export, and automatic migration of prior records, all of which imply collection, processing, sharing, and persistence of potentially sensitive business data. In an enterprise decision-support context, failing to disclose what data is fetched, stored, exported, shared with collaborators, or migrated can lead to inadvertent exposure of confidential strategy, investment, or operational information.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.