Back to skill

Security audit

Content Audit

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed social-content audit workflow that reads user-provided account analytics and recommends changes without taking action itself.

Installers should understand that this skill may analyze social account performance data through related analytics workflows. Confirm intent before sharing analytics, and review recommendations manually before changing or deleting content.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The description contains very broad natural-language trigger phrases such as 'what's working and what isn't' and 'I post a lot but it's not working,' which can overlap with ordinary user requests and cause the skill to be invoked when the user did not explicitly intend a content audit. Unintended invocation can route conversations into account-analysis workflows, potentially pulling in other connected skills or data sources and producing irrelevant or privacy-impacting processing.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.