C Suite Coach Video

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only marketing skill for creating corporate training video content, with no hidden code, data access, or persistence.

Reasonable to install for corporate training and coaching video marketing help. Users should avoid pasting confidential client details, employee personal data, or unapproved ROI figures into prompts, and should review generated claims before publishing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill includes a generic activation phrase, "Activate this skill to," followed by broad content-generation tasks without clear trigger conditions, scope limits, or user-intent checks. In an agent environment, this can cause the skill to be invoked in situations where the user did not explicitly request it, leading to inappropriate prompt injection of marketing behavior or unintended task hijacking.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal