Landing Page Builder

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward landing-page generator, with the main caution that generated pages may preserve or include browser JavaScript.

Use trusted HTML templates, and review any preserved JavaScript, forms, external fonts, images, videos, or embeds before publishing. When saving output, choose the destination path deliberately and avoid overwriting existing work.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs the agent to save a generated HTML file into the user's workspace or a specified path without requiring confirmation. Any agent action that writes files on the user's behalf should be gated by explicit consent, because unexpected file creation can overwrite existing work, place content in sensitive locations, or be abused in prompt-injection chains to persist untrusted output.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal