Industry Research Advisor

Security checks across malware telemetry and agentic risk

Overview

This is a simple industry report-writing skill that uses public web research and shows no hidden or harmful behavior.

Safe to install for structured industry research. Expect it to use web searches and cited public sources; review the sources and assumptions before relying on its recommendations for business, investment, legal, or regulatory decisions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill’s invocation guidance uses very broad phrases such as 'industry analysis' and 'industry research' that are common across many benign user requests. This can cause over-triggering or ambiguous routing, where the skill is selected for queries outside its intended scope, increasing the chance of inappropriate tool use, misleading outputs, or interference with more suitable skills.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal