Competitor Analysis Report

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward public-research report generator that writes local report files, with no evidence of hidden execution, credential access, or data exfiltration.

Reasonable to install for public competitive research. Review any proposed shell command before allowing it, and be aware the generated Markdown, HTML, summary, and CSV files may contain business-sensitive analysis saved locally in output/competitor-analysis/.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
95% confidence
Finding
The skill explicitly instructs the agent to create several files under output/competitor-analysis/ but does not warn the user up front that filesystem writes will occur. This can lead to unexpected artifact creation, overwrite risk, or disclosure of sensitive business analysis to local storage, especially in environments where users expect read-only research behavior.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal