Back to skill

Security audit

CRM analysis with OutboundSync

Security checks across malware telemetry and agentic risk

Overview

This skill is a read-only CRM analysis guide with clear scope limits and no executable install or persistence behavior.

Install only where the agent has appropriate read access to CRM data. Because CRM fields may contain personal contact details and message text, limit access to the fields needed for the analysis, avoid pasting secrets or unnecessary message bodies into prompts, and rely on the skill's partial/unsupported outputs when required signals are missing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The documentation shows that full email and social message content, subjects, addresses, and profile data are synchronized into HubSpot contact properties, but it does not warn about privacy, consent, retention, or sensitive-data handling. In a CRM analytics skill, this can normalize storing message bodies in broadly accessible CRM fields, increasing the risk of over-collection, internal exposure, and regulatory noncompliance if users ingest personal or sensitive content.

VirusTotal

VirusTotal engine telemetry is currently stale for this artifact.

View on VirusTotal

Static analysis

No suspicious patterns detected.