Back to skill

Security audit

Ai Cgo

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed growth-strategy assistant with some routing and automation cautions, but no hidden executable behavior or malware signal.

Install this only if you want an AI growth-planning assistant. Review any recommendations before applying them to budgets, pricing, ad bidding, customer segmentation, public campaigns, or persistent knowledge files, and prefer explicit human approval for real business changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The skill metadata and body strongly bias operation toward Chinese-language behavior through Chinese trigger phrases, headings, and operational instructions without any explicit user-language preference check. This can cause unintended language switching, reduce user comprehension, and create prompt-routing errors or misleading outputs when the user did not request Chinese, which is a real safety and quality issue in multilingual systems.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The routing phrases are broad and semantically overlapping (for example, generic words like "build," "design," "improve," and "optimize"), which can cause ordinary requests to be routed into this skill unintentionally. In a growth-orchestration skill, misrouting can expose users to the wrong automation, advice path, or downstream workflow selection, reducing reliability and potentially causing unsafe or irrelevant business actions.

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.