Back to skill

Security audit

Diting Compensation Expert

Security checks across malware telemetry and agentic risk

Overview

This skill is a compensation-analysis guide that uses sensitive HR data in a purpose-aligned way, but users should minimize and protect employee-level data before using it.

Before installing or using this skill, treat any employee-level salary file as highly sensitive. Prefer pseudonyms or employee IDs instead of names, remove fields not needed for the specific analysis, restrict access to authorized HR or leadership users, and delete working files when the analysis is complete.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The file defines a standardized CSV template for collecting highly sensitive HR data, including names, employee IDs, compensation, gender, age, education, contract type, and performance ratings, but provides no privacy, minimization, access control, retention, or de-identification guidance. In a compensation-analysis skill, this omission is particularly dangerous because it operationalizes bulk collection and processing of personal and potentially regulated employee data, increasing the risk of privacy violations, insider misuse, and noncompliant handling.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.