Back to skill

Security audit

Product Data Collection

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only skill for a product data task API; it uses an auth token and can change remote task records, but those abilities are clearly disclosed and match its purpose.

Install only if you trust the product-task API and can provide a properly scoped authorization value. Treat create, update, and batch-update as actions that can change remote data, verify filters and target environment before use, and keep PRODUCT_TASK_AUTH out of chats, logs, screenshots, and source files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.generated_source_template_injection

User-controlled placeholder is embedded directly into generated source code.

Critical
Code
suspicious.generated_source_template_injection
Location
SKILL.md:23