Data Enrichment

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only data enrichment skill that fits its stated purpose, but users should handle contact and CRM data carefully.

Install only if you are allowed to process the company and contact data involved. Use lawful and permitted public sources, avoid sensitive personal data, check source terms and privacy obligations, verify enriched records before use, and review CRM imports in small batches or a sandbox before operational use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
This skill explicitly supports enrichment, scoring, and CRM export of company and contact records, including personal data such as names, titles, LinkedIn URLs, and recent activity, but it provides no privacy, consent, retention, or compliance guidance. In a workflow designed to aggregate and operationalize contact data at scale, that omission can lead users to collect, merge, and export personal information in ways that violate internal policy or privacy regulations.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal