Back to skill

Security audit

Csv To Task

Security checks across malware telemetry and agentic risk

Overview

This is a text-only CSV-to-task conversion skill with no hidden data access, network use, persistence, or privileged behavior found.

Before installing, understand that the skill will read and transform CSV data you provide. Review generated tasks before importing them into Jira, Linear, Notion, or another task system, especially if the CSV includes internal names, emails, deadlines, or project details.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger condition is broadly defined as any CSV input plus a task/todo/ticket creation intent, which can overlap with common user requests and cause the skill to activate when the user did not intend structured task generation. In an agent setting, over-broad invocation can lead to incorrect transformations, unwanted task creation, or misrouting user data into the wrong workflow.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.