Back to skill

Security audit

Podcast And Audiograms

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent podcast repurposing guide that asks for relevant episode and brand materials and does not include hidden execution or credential-handling behavior.

Before installing, confirm you are comfortable giving the agent access to your brand profile, episode transcript or recording, and retention data for repurposing work. Review all generated clips, captions, CTAs, and scheduled posts before publishing, and only use content you own or have permission to clip.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Low
Confidence
81% confidence
Finding
This manifest-style JSON includes example inputs such as "Help me turn my podcast into social clips." that use broad conversational phrasing. In manifest-like skill metadata, such unspecific trigger wording can overlap with ordinary requests unless the activation scope is explicitly constrained elsewhere.

Vague Triggers

Low
Confidence
79% confidence
Finding
The input "Make me some podcast clips." is concise but still functions as a broad natural-language trigger example without clarifying when the skill should not activate. For manifest/eval content, this can leave trigger scope ambiguous if these examples are reused to define invocation behavior.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.