Back to skill

Security audit

Rolling Suds Customer Quote Intake

Security checks across malware telemetry and agentic risk

Overview

This markdown-only skill formats customer quote intake into internal notes and handoffs, with no code execution or system access, though it may handle user-supplied customer details.

Installers should be comfortable using this skill with customer lead information. Review generated notes before pasting into Workiz or another estimator, and only provide customer addresses, photos, or scheduling details when authorized for business intake.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
This markdown skill explicitly instructs the agent to ingest customer communications and identifying details such as addresses and photos. The description does not include any warning about privacy, sensitive data handling, or verifying that sharing customer information is appropriate, which is relevant because markdown files should warn about behaviors affecting user data or privacy.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.