Open Agreements

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed legal-template helper that can use hosted processing or DocuSign, with sensitive data flows explained and no hidden executable payloads found.

Install only if you are comfortable using a tool for legal-document drafting. Use the local CLI path for confidential agreements; use remote MCP or DocuSign only when you accept sending contract contents, field values, and signer details to those services. Review generated documents carefully before authorizing any signature workflow.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal