business-analyst

Security checks across malware telemetry and agentic risk

Overview

This is a markdown-only business-analysis prompt skill with no evidence of hidden execution, credential access, persistence, or unsafe data handling.

This skill is reasonable to install for drafting business process analyses, roadmaps, ROI estimates, and change-management plans. Users should still review recommendations before acting, especially where budgets, staffing, automation, compliance, or operational changes are involved, and avoid treating its financial or risk estimates as authoritative without validating the source data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill description is overly broad and can cause the agent to invoke this skill for loosely related business, strategy, risk, or process questions without clear boundaries. Overbroad routing increases the chance of inappropriate delegation, which can expose sensitive business context to the skill unnecessarily or produce unreliable outputs outside the intended scope.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal