Back to skill

Security audit

Audience Research

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent audience-research workflow, but users should avoid putting private customer details into its language-bank output.

Install only if you are comfortable with an audience-research skill that may summarize or quote customer language into audience.md. Use public sources or materials you are authorized to use, redact names and identifiers, and avoid including sensitive support, DM, or sales-call details unless your organization permits that use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The file explicitly directs collection of user language from reviews, social comments, Reddit, forums, Discords, support tickets, sales-call notes, DMs, and customer conversations, but provides no privacy, consent, data-minimization, or retention safeguards. This creates a real risk of gathering personal or sensitive data from semi-private or private channels and reusing it in downstream artifacts such as `audience.md`, potentially violating platform terms, privacy expectations, or internal data-handling policies.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.