Content Audit Expert

Security checks across malware telemetry and agentic risk

Overview

This is a coherent content-auditing skill, with the main caution that audited drafts may be shared with OpenAI or connected collaboration tools.

Install only if you are comfortable using an OpenAI API key and sharing the content you audit with the services you choose, such as OpenAI, Google Docs, Slack, or WordPress. Avoid confidential, regulated, customer-sensitive, or unpublished material unless your organization permits those services for that data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill encourages users to share Google Docs links and use Slack/WordPress integrations without clearly warning that document contents, metadata, or workspace information may be transmitted to external AI services for analysis. This creates a real risk of unintended disclosure of confidential or regulated content, especially in enterprise environments where users may assume integrated tools are internal-only.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal