Back to skill

Security audit

Newsletter Team — Agent Configuration Bundle

Security checks across malware telemetry and agentic risk

Overview

This is a coherent newsletter workflow skill with disclosed file, web, memory, and approval-gated scheduling capabilities, and no hidden executable behavior.

Before installing, check where the team will save drafts or saved articles, what memory it will retain for personalization, and what calendar or scheduling system is connected for approval-gated event changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The skill grants multiple roles file_write capability and gives the scheduler authority for approval-gated scheduling/event mutations, but the description does not clearly warn users about data-modifying or externally impactful actions. This can cause users to invoke the skill without understanding that it may alter files or calendars, increasing the risk of unintended data changes or operational side effects.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.