Firm Saas Pack

Security checks across malware telemetry and agentic risk

Overview

This is a transparent SaaS orchestration skill made only of instructions, with broad session tools disclosed but no hidden code or malicious behavior found.

Install this only if you want a broad SaaS multi-agent planning bundle. Review the optional companion skills before installing them, especially tools that can merge PRs or export to Jira/docs, and avoid placing sensitive customer or company data in shared sessions unless the workspace and agents are appropriately scoped.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill advertises broad activation of multiple departments and agent capabilities without defining narrow trigger conditions, approval boundaries, or scoped use criteria. In a multi-agent/orchestration environment, this can cause overbroad invocation, unintended task routing, and expanded access to powerful session tools, increasing the chance of unsafe actions or excessive autonomy.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal