Back to skill

Security audit

Reverse Compliance

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed compliance-planning assistant that uses OpenAI for generation and does not show hidden persistence, destructive actions, or credential misuse.

Install only if you are comfortable configuring an OpenAI API key and sending the business, product, market, or compliance details you provide to OpenAI for generation. Treat outputs as draft planning material, not legal advice, and have qualified compliance or legal professionals verify them before filing documents, changing labels, listing products, or making market-entry decisions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The README explicitly states that the skill relies on a cloud service and the OpenAI API, but it does not tell users what data may be sent off-device, retained, or processed by third parties. In a compliance-focused skill, this omission is especially risky because users may input sensitive legal, product, or cross-border business information under the assumption that the workflow is privacy-aware.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger list contains broad, common phrases such as compliance-related keywords that are likely to appear in ordinary user discussions, which can cause the skill to activate outside a clearly scoped intent. In this context, overbroad activation is security-relevant because the skill is positioned to provide strategic regulatory guidance, so accidental invocation could steer unrelated conversations into high-stakes compliance or business advice without explicit user opt-in.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The article explicitly instructs users to configure an OpenAI API key and references setting it as an environment variable, but provides no guidance on secret handling, storage, rotation, or avoiding exposure in prompts, screenshots, repos, or logs. In a deployable skill/install context, this omission can lead users to paste credentials into unsafe locations or mishandle them during setup, resulting in account abuse or unauthorized API usage.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.