mar-content-strategy

Security checks across malware telemetry and agentic risk

Overview

This is a text-only content strategy guide with no code, installs, credential requests, or hidden system access.

This skill is low technical risk. Before installing or using it, be careful not to paste raw customer tickets, call transcripts, private community posts, or personal data into the agent; summarize or anonymize them, and review any content before posting or sending it publicly.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger list is very broad and includes generic phrases like 'content ideas', 'content plan', and 'what content should I create', which can cause the skill to activate in situations where the user did not specifically request this skill. Unintended invocation can lead to irrelevant guidance, routing mistakes, and increased exposure of the skill's instructions in contexts where another skill would be more appropriate.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal