Back to skill

Security audit

Founder Content

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only content drafting skill whose repository-context and platform guidance are disclosed and aligned with founder content creation, with review needed before sharing sensitive project details.

Safe to install as a drafting aid. Before using build-in-public auto mode, confirm which repository or PR data the agent may inspect, and review every generated post for unreleased features, private metrics, customer information, or sensitive business details before publishing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
86% confidence
Finding
The skill documentation expands from content generation into automated repository-triggered storage and multi-platform posting, which materially changes the effective capability surface from drafting text to initiating actions based on repo events. In an agent setting, that can lead to unapproved access to development artifacts and unintended publication workflows the user did not explicitly authorize.

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
The 'auto mode' description says the skill may pull recent commits, PR titles, descriptions, and release notes, which exceeds a normal content-writing scope and implies inspection of potentially sensitive internal development data. Without strong disclosure and opt-in, this creates a risk of over-broad data access and accidental exposure of confidential roadmap or code-adjacent information in generated content.

Context-Inappropriate Capability

Medium
Confidence
84% confidence
Finding
Automatic posting and trigger-based distribution move the skill from advisory assistance into operational execution on external platforms. That increases the risk of accidental spam, reputational harm, or disclosure of sensitive product information if posts are generated or published without explicit review and approval.

Vague Triggers

High
Confidence
91% confidence
Finding
The manifest uses very broad trigger phrases such as 'any content creation request,' which can cause the skill to activate in contexts the user did not intend. Over-broad invocation increases the chance that the skill injects its workflow, including research and possible repo-inspection behaviors, into unrelated tasks and expands data exposure or unintended actions.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill omits a prominent warning that 'auto mode' may inspect version-control data, while examples also normalize automatic posting behavior. In practice, this undermines informed consent: users may invoke a writing assistant without realizing it may read internal repo metadata or prepare outward-facing content from it.

VirusTotal

No VirusTotal findings

View on VirusTotal