Back to skill

Security audit

Data Privacy Law Explainer

Security checks across malware telemetry and agentic risk

Overview

This is an offline legal-information skill with state privacy-law notes and no executable code, credential handling, persistence, or hidden data flow.

This appears safe to install as an informational legal explainer. Treat its legal content as a dated snapshot, verify current law before relying on it, and do not provide private business facts for the optional refresh because the skill itself says only the fixed canonical URL should be fetched.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

57/57 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.