Back to skill

Security audit

Cap Table Manager

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward cap table modeling skill, but users should treat the business and ownership data they enter as confidential.

Install only if you are comfortable entering sensitive company ownership and financing information into your agent environment. Prefer placeholders or redacted stakeholder names when possible, and export CSV or Sheets outputs only to approved, access-controlled locations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly solicits and structures highly sensitive cap table, financing, and financial data, then encourages export to CSV/Sheets without any confidentiality warning, data minimization guidance, or handling restrictions. In this context, ownership data, investor terms, runway, and valuation inputs are materially sensitive and could expose a company to privacy, competitive, legal, and deal-process risk if shared with the wrong system, logged insecurely, or exported broadly.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal