Post Show Followup

Security checks across malware telemetry and agentic risk

Overview

This skill is a documentation-only aid for drafting trade-show follow-up emails, with a privacy caution around the lead/contact data users may paste into it.

Safe to install as a drafting aid. Before use, avoid pasting unnecessary personal data, private CRM notes, regulated details, or confidential customer information; confirm you have permission to use contacts for outreach, and review generated emails for accuracy, consent, compliance, and over-personalization before sending.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
This skill is designed to process lead and contact information, conversation notes, CRM merge tags, and potentially business-card data, yet it provides no privacy or data-handling warning. That omission increases the chance users will paste personal data, sensitive notes, or regulated contact details into the skill without minimization or consent considerations, leading to privacy, compliance, or data exposure issues.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal