User Guide Automation

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed browser-documentation workflow, with normal screenshot and optional credential use for its stated purpose but some care needed around sensitive app data.

Use this skill with a test or least-privilege account when possible, scope it to the needed feature, and review the Markdown and screenshots before sharing because they may include sensitive screen contents. Avoid providing production passwords unless necessary; manual login or temporary credentials are safer.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly asks for and uses user credentials for browser-driven interaction, but provides no guidance on minimizing, masking, securely handling, or avoiding persistence of secrets. In an agent workflow that may log prompts, screenshots, browser state, or generated artifacts, this can lead to unnecessary exposure of usernames, passwords, session details, or privileged access paths.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal