Security audit
Data Privacy Law Explainer
Security checks across malware telemetry and agentic risk
Overview
This is an offline legal-information skill with state privacy-law notes and no executable code, credential handling, persistence, or hidden data flow.
This appears safe to install as an informational legal explainer. Treat its legal content as a dated snapshot, verify current law before relying on it, and do not provide private business facts for the optional refresh because the skill itself says only the fixed canonical URL should be fetched.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
57/57 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
