Eu Ai Act Compliance

Security checks across malware telemetry and agentic risk

Overview

The skill appears to provide compliance guidance, with no evidence of code execution or hidden access, but users should avoid entering real HR or candidate data.

Use this skill with redacted or synthetic examples. Do not paste real candidate, employee, medical, demographic, disciplinary, or performance data unless you have approved handling controls, and treat its compliance output as a starting point rather than legal advice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The README encourages users to seek AI Act, GDPR, and HR compliance assessments for recruitment and performance tools, which are likely to involve sensitive personal, employment, and potentially special-category data. Without an explicit warning to avoid pasting real candidate/employee data or to anonymize inputs, users may disclose regulated information into the skill flow, creating privacy, confidentiality, and downstream handling risks.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal