Back to skill

Security audit

competitor-analyzer

Security checks across malware telemetry and agentic risk

Overview

This skill performs competitor research using disclosed MCP integrations and writes reports to memory, with privacy and persistence caveats users should understand.

Install only if you are comfortable sending competitor research inputs and review data to the configured MCP services and storing generated reports in memory. Avoid using sensitive internal strategy, confidential product plans, or private customer data unless your MCP and memory retention settings are appropriate.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger language is broad and loosely scoped, which can cause the agent to invoke this skill in situations where the user did not clearly intend competitor scraping, external transmission, or persistent report generation. Over-broad activation increases the chance of unnecessary data collection and side effects, especially because the workflow can write reports to memory and call external MCP/HTTP services.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The workflow states that analysis results are synchronously written to `memory/competitor-analysis/YYYY-MM-DD.md`, but the skill description does not prominently warn users that their inputs and derived market intelligence will be persisted. Silent persistence can expose sensitive business research, URLs, and review data to later sessions or other components with memory access.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill transmits keywords, product URLs, market data, and review content to external MCP services and may even fall back to direct HTTP access, but it does not provide a clear privacy warning or data-handling disclosure. This creates a real risk of leaking user-provided commercial research inputs or third-party content to external systems without informed consent.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.