Back to skill

Security audit

Trade Show Competitor Radar

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed markdown-only workflow for turning user-provided trade show observations into structured competitive intelligence, with a privacy-related caution around identifying booth visitors.

Before installing, be aware that the skill may encourage recording or acting on identities of people seen at competitor booths. Use it only with information your organization is allowed to collect and use, and avoid adding personal data unless you have a valid business and privacy basis.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Low
Confidence
78% confidence
Finding
The description embeds multiple languages inline, but the skill does not state whether users may interact in their preferred language or whether any locale behavior is optional. Under the policy rule, language behavior should either be user-selectable or clearly justified as region-specific.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The markdown directs the model to include 'Contacts to Flag' for visitors observed at a competitor booth, which can involve collecting or acting on personal data. The skill description does not warn users about privacy, consent, or internal policy requirements before using observed attendee identities for outreach.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.