Back to skill

Security audit

AI PM Intel Brief

Security checks across malware telemetry and agentic risk

Overview

This is a low-risk briefing skill that summarizes public AI product-management signals, with only minor routing and language-template caveats.

Install this if you want an opinionated AI-PM social-signal briefing workflow. Be aware it may route some generic news or trend-summary requests into this skill and may default to a Chinese brief template; keep external collection limited to intended public sources and avoid granting unnecessary account/session access.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The description contains multiple broad trigger phrases such as generic requests for a news brief, trend roundup, or '整理成简报', which can cause the skill to activate for common summarization tasks outside its intended AI-PM/social-intel niche. Over-broad invocation increases the chance of unintended routing, causing the agent to apply this skill in the wrong context and potentially fetch external content or shape output in ways the user did not intend.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.