Back to skill

Security audit

Ai Stack Builder

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only tool-recommendation skill with privacy caveats around third-party AI services, but no hidden execution or system access.

Safe to install as a recommendation aid. Before following its suggestions, verify current pricing and privacy terms, and do not paste confidential, customer, regulated, copyrighted, or third-party material into external AI tools unless you are authorized and the vendor is approved for that data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill tells users to paste notes, SOPs, and meeting notes into third-party services without any warning about confidentiality, retention, or data-sharing risks. This can lead users to expose internal documents, personal data, or regulated information to external platforms that may store, train on, or further process that content.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill recommends meeting-intelligence and video-processing workflows that may involve recording, transcription, or repurposing third-party content, but it omits consent, privacy, and rights considerations. Users could process calls or videos without participant permission or without the right to reuse the content, creating legal, privacy, and trust risks.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.