Global Customer Agent

Security checks across malware telemetry and agentic risk

Overview

This is a simple multilingual customer-service prompt template, with no code or hidden access, but real customer quotes should be reviewed before sending.

Safe to install as a template. Before using it in a live customer channel, require human approval for pricing, shipping, payment terms, and contractual language, and let operators confirm or override the detected customer language.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
80% confidence
Finding
The skill mandates automatic language detection and reply generation without giving the user a way to confirm or select their language. This can cause misclassification, unintended disclosure, inaccurate transactional communication such as pricing or terms, and poor handling of regulated or high-stakes customer interactions across languages.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal