Back to skill

Security audit

influence-and-negotiation

Security checks across malware telemetry and agentic risk

Overview

This negotiation coaching skill is related to its stated purpose, but it can broadly gather and persist sensitive workplace, business, and personal information without clear opt-in limits.

Install only if you are comfortable with a negotiation assistant accessing connected business systems and creating persistent negotiation notes. Before use, limit which sources it may access, avoid privileged or regulated material unless authorized, redact unnecessary personal data, and review or delete generated memory files after the engagement.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The skill presents itself as negotiation coaching but instructs the agent to perform broad internal and external intelligence gathering, including parallel sub-agents across CRM, Slack, LinkedIn, and OSINT. That materially expands data access and collection beyond what many users would reasonably expect from a drafting/coaching tool, creating a risk of unnecessary exposure of sensitive employee, customer, or deal information.

Context-Inappropriate Capability

Medium
Confidence
89% confidence
Finding
Directing the agent to profile named stakeholders across CRM, Slack, LinkedIn, and OSINT encourages aggregation of personal and contextual information that may be irrelevant, sensitive, or privacy-invasive. In a negotiation context, this can also facilitate covert persuasion based on nonessential personal intelligence rather than task-limited business context.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger language is extremely broad and overlaps with ordinary workplace communication, making it likely the skill will activate in situations users did not intend as formal negotiation support. Because the skill also authorizes research, drafting, and sub-agent behavior, ambiguous activation increases the chance of unnecessary data access and over-collection.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The instruction that pasted text or ordinary conversational cues should trigger the skill, without clear activation limits, creates implicit invocation risk. In practice this can cause the agent to enter a heavyweight workflow, load references, and pursue intelligence-gathering steps when the user may have only wanted lightweight feedback or drafting assistance.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill instructs the agent to proactively pull broad context from connected systems like email, chat, CRM, calendars, and cloud storage before proceeding, without requiring explicit informed consent, scope confirmation, or minimization. This creates a real risk of oversharing confidential business, HR, legal, or third-party personal data far beyond what is necessary for the immediate task.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The intake text asks users to share highly sensitive materials such as HR case files, compensation grids, legal memos, union minutes, internal approval chains, and off-record signals, while framing more data as always better. Without warnings about confidentiality, privilege, consent, or redaction, users may disclose protected or unnecessary information that should not be processed or retained.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill explicitly tells the agent to proactively create and continuously update persistent negotiation memory files, even when the user did not ask for persistence. In a negotiation context, these files are likely to contain sensitive personal, employment, commercial, and strategic information, so automatic retention without an explicit consent, minimization, or privacy warning creates a real risk of oversharing, unintended storage, and cross-session leakage.

Ssd 3

High
Confidence
97% confidence
Finding
The skill goes beyond analyzing user-provided input and directs the agent to proactively collect extensive communications and documents from connected systems, including third-party messages and internal records. That materially increases the chance of unauthorized aggregation of sensitive data and creates a surveillance-like collection pattern inconsistent with least-privilege and data-minimization principles.

Ssd 3

High
Confidence
98% confidence
Finding
The skill instructs exhaustive searches across all available sources, use of multiple sub-agents, cross-referencing of contradictions, and storage of extracted intelligence in memory files, including rumors, low-confidence signals, and 'grey' intelligence for internal use. This is dangerous because it normalizes persistent aggregation of sensitive personal and corporate information, expands exposure through parallel processing, and risks retention of unverified or improperly sourced data that could later be misused or leaked.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.