Home Inspection

Security checks across malware telemetry and agentic risk

Overview

This is a coherent home-inspection checklist and report generator; its main privacy consideration is that reports can include a full residential address.

Install is reasonable if you need a local Taiwan home-inspection guide. Before using it, decide whether a full address is necessary, store input JSON and generated reports privately, and redact addresses before sharing reports with people or systems that do not need the exact location.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill instructs collection of a precise residential address and other property details without any privacy notice, minimization guidance, or retention limits. Residential addresses are sensitive personal data; if logged, shared in reports, or reused across integrated skills, this can expose occupant location and ownership-related information.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The example report schema embeds the full property address directly in the JSON output, encouraging persistent storage and transmission of exact location data without warning. In a home-inspection context, this increases privacy risk because reports may be shared with buyers, sellers, agents, contractors, or other systems.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal