Grants Program Marketing

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed, instruction-only guide for Web3 grants marketing and operations, with no code execution or hidden data access.

Before installing, treat this as a marketing and review template. Review any generated announcements, DMs, scorecards, and reports before posting or using them for funding decisions, and avoid entering confidential applicant data or treasury credentials unless you intentionally provide that context.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger description is genuinely overbroad: it includes many generic phrases plus a catch-all covering 'any variation' of funding program management in Web3/DAO contexts. In an agent system, this can cause unintended invocation on loosely related requests, leading to misrouting, irrelevant automation, or the skill shaping responses outside its intended scope.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal