Back to skill

Security audit

01 Complaint Classification

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a complaint-processing aid with a privacy hygiene gap in its examples, not evidence of malicious or hidden behavior.

Install only if you are comfortable reviewing complaint text with the agent. Treat order numbers, names, addresses, account details, and complaint facts as sensitive: redact or replace them with placeholders unless the information is strictly needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The examples include a realistic order number and detailed complaint facts without any accompanying guidance on masking, minimizing, or safely handling potentially sensitive user data. In a complaint-processing skill, this can normalize collecting and reproducing identifiers and case details in prompts, logs, and training materials, increasing privacy and data-handling risk.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal