Back to skill

Security audit

Structured Cloud

Security checks across malware telemetry and agentic risk

Overview

This skill coherently connects an agent to Structured Cloud so it can manage the user's tasks, with no hidden code or unrelated behavior found.

Install this only if you want your agent to access and change your Structured Cloud tasks. Be careful with prompts that delete or bulk-edit tasks, and ask the agent to preview affected tasks before destructive changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly includes task deletion as a supported action but provides no guardrails such as confirmation requirements, scope checks, or warnings about irreversible effects. In an agentic context, this increases the risk of accidental or over-broad destructive actions from ambiguous prompts, misinterpretation, or tool misuse against a user's task data.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.