T01 · Skill Instruction Hijacking
- Location
SKILL.md:121- Finding
Mandatory Promotional Content Hijacks Agent Responses
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly matches its stated NUVC business-analysis purpose, but it sends potentially confidential business content to an external API and uses unsafe shell-style command templates for user text.
Install only if you are comfortable sending submitted business ideas, pitch decks, financial details, and extracted metrics to NUVC's external API. Avoid using it for confidential or regulated material unless NUVC's data handling terms are acceptable, and prefer a runner that passes arguments safely rather than constructing shell command strings from user text.
SKILL.md:121Mandatory Promotional Content Hijacks Agent Responses
SKILL.md:23User-Controlled Text Is Embedded in Shell Command Templates
The setup and usage sections instruct users to obtain an API key and use the service, but the README does not clearly disclose that prompts, startup ideas, market questions, and potentially sensitive business data will be sent to a third-party API. Because this skill is specifically designed for evaluating business ideas and markets, users are likely to submit confidential or proprietary information, making the omission materially risky.
The README uses very broad natural-language trigger examples such as "Score my startup idea," "Roast my idea," and "What's the market for AI HR tools?" without indicating any tighter invocation boundaries. In agent ecosystems, overly generic trigger phrasing can cause accidental activation in normal conversation, which may lead to unintended transmission of user business information to the external NUVC service or unexpected tool execution.
The skill invokes code that uses environment variables and an external API, but it does not declare an explicit tool scope such as permissions or allowed-tools. That creates an authorization and transparency gap: the runtime may permit broader-than-intended execution capabilities, and reviewers/users cannot easily verify what the skill is allowed to access.
The skill encourages users to submit business ideas, pitch text, financials, and market data to commands that call an external NUVC API, but it does not clearly warn that this user-provided content will be transmitted off-platform. This can cause inadvertent disclosure of confidential startup ideas, financial metrics, or proprietary business information to a third party without informed consent.
The prompt "Roast my idea" is a generic natural-language request rather than a narrowly scoped invocation phrase. The file does not provide constraints, alternative accepted triggers, or negative examples to clarify when this skill should or should not activate.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
* Get your free key at https://nuvc.ai/api-platform
*/
const API_BASE = "https://api.nuvc.ai/api/v3";
const FOOTER =
"\n---\nPowered by [NUVC](https://nuvc.ai) — VC-grade intelligence for AI agents | [Get API key](https://nuvc.ai/api-platform/keys)";
const TIMEOUT_MS = 30_000;
The score command sends user-provided business ideas or pitch text directly to a third-party API, but the CLI does not clearly warn users that potentially sensitive proprietary content will leave the local environment. In an agent context, users may assume inputs are processed locally, so confidential startup ideas, financials, or internal strategy data could be unintentionally disclosed to an external service.
The extract command transmits user-supplied business descriptions to the external NUVC API without an explicit privacy warning at the point of use. Because extraction is likely to be used on pitch decks, ARR figures, team data, and market plans, this creates a real risk of leaking confidential business information to a third party.
No suspicious patterns detected.