Data Analyst Agent

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only book analytics skill, but it describes recurring collection, storage, and sharing of potentially private platform revenue and reader data without clear access boundaries or user controls.

Review before installing. Use it only if you are comfortable defining exactly which book platforms, exports, or public pages it may analyze. Do not provide publishing account credentials or private revenue data unless the skill is updated to state allowed sources, consent requirements, storage and deletion rules, schedule controls, and which other agents may receive reports.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill description is broad enough to trigger on many generic data-analysis requests without clear exclusions, which can cause the wrong skill to activate and handle data it was not intended to process. In a multi-agent system, this increases the risk of unintended access, privacy overreach, or misleading outputs because the agent may collect or analyze platform data outside its proper scope.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal