Newsletter Generator

Security checks across malware telemetry and agentic risk

Overview

This skill appears to create local newsletter draft files and does not show hidden data access, sending, persistence, or destructive behavior.

Safe to install for local newsletter draft generation. Treat generated content as a draft: verify sources, replace placeholder affiliate links, confirm disclosures and endorsement claims, and only use subscriber segments or engagement data that you are authorized to process under applicable privacy and email-marketing rules.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
80% confidence
Finding
The description is broad enough to match generic requests about email lists, newsletters, engagement, or monetization, which can cause the skill to activate outside a narrowly intended context. Over-broad triggering is dangerous because it may expose affiliate-link insertion, content generation, and file-writing behavior in situations where the user did not intend those actions or where stricter review should apply.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill promotes personalization using subscriber segments, past engagement data, time zones, preferences, and analytics without any privacy, consent, retention, or compliance guidance. In an email-marketing context, this makes misuse more dangerous because it encourages processing potentially regulated personal data without guardrails, creating risks of privacy violations, unlawful profiling, and data leakage.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal