Back to skill

Security audit

research-analysis

Security checks across malware telemetry and agentic risk

Overview

This is a coherent business research skill that openly guides web/company-data lookups and chart generation, with privacy caution needed for user-research outputs.

Before installing, expect this skill to use web searches, public page fetching, optional Tianyancha connector data, and CDN-hosted chart libraries during research tasks. For user research, only process data you are allowed to use, avoid unnecessary sensitive attributes, and anonymize or aggregate interview and survey details in final reports.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Scope Creep

High
Confidence
96% confidence
Finding
The manifest declares no permissions, yet the skill explicitly instructs the agent to use external connectors and network-capable tools such as Tianyancha MCP, WebSearch, WebFetch, and CDN-hosted visualization libraries. This creates a capability/metadata mismatch that can mislead users or policy enforcement systems about what the skill will attempt to do, increasing the risk of unauthorized data access, exfiltration, or unexpected outbound requests during execution.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The description uses broad trigger phrases such as 'analyze this market,' 'compare competitors,' and 'any business research task,' which can cause the skill to activate for a wide range of loosely related prompts. Overbroad activation increases the chance that the skill will run in contexts where external data collection, connector use, or web fetching is unnecessary or inappropriate, expanding the attack surface and enabling unintended tool usage.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The persona framework explicitly encourages collecting and organizing demographic, behavioral, purchasing, and psychological user data, including sensitive preferences and motivations, but provides no guidance on consent, data minimization, anonymization, or lawful handling. In a research skill, this omission can lead users to create research artifacts that over-collect personal data or expose sensitive respondent information in ways that violate privacy expectations or policy.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The report template instructs users to include interview record summaries and questionnaire data details in an appendix without any warning to redact identifiers or limit dissemination. This creates a concrete risk that raw or quasi-identifiable respondent data will be copied into final reports and shared beyond the original research context.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.