Back to skill

Security audit

赛博销售

Security checks across malware telemetry and agentic risk

Overview

This sales-coaching skill is coherent, but it asks the agent to process private customer chats, screenshots, and call transcripts without privacy safeguards or clear consent boundaries.

Install only if users understand that customer chats, call transcripts, screenshots, and voice-message content may be analyzed and echoed back. Redact names, phone numbers, account details, pricing, contracts, internal strategy, and any third-party private information before use, and avoid uploading recordings or messages unless you have the right to share them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger description is extremely broad and covers common sales-adjacent phrases, screenshots, calls, and customer-response questions. This can cause the skill to activate in many ordinary conversations and ingest sensitive business or personal communications without clear user intent, increasing the chance of privacy over-collection and inappropriate intervention.

Missing User Warnings

High
Confidence
99% confidence
Finding
The skill explicitly invites users to submit chat screenshots, call transcripts, voice messages, emails, and similar materials, but provides no privacy warning, redaction guidance, or consent check. Because these materials routinely contain names, contact details, financial data, internal business information, and third-party communications, the omission materially raises the risk of unnecessary disclosure.

Ssd 3

Medium
Confidence
95% confidence
Finding
The skill instructs the model to extract full conversation content from screenshots, recordings, and text, including contextual details and platform metadata. That creates avoidable exposure of sensitive personal and business information, especially when only a limited subset is needed for coaching, and it increases the chance of reproducing confidential data in outputs or logs.

Ssd 3

Medium
Confidence
97% confidence
Finding
The required output format tells the model to quote original customer statements verbatim. Verbatim quoting can unnecessarily echo confidential or personal content from private chats and calls, amplifying disclosure risk in the response even when a paraphrase would be sufficient.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.