Back to skill

Security audit

Stainless Competitor Intel

Security checks across malware telemetry and agentic risk

Overview

This skill is an instruction-only competitor research template, but it explicitly encourages deceptive competitor intelligence gathering such as pretending to be a customer.

Install only if you will restrict use to public, authorized, and properly sourced competitor research. Do not use the skill to impersonate customers, induce suppliers or customers to reveal confidential information, or publish unverified claims about competitors.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill explicitly recommends deceptive intelligence-gathering tactics such as 'pretending to be a customer to ask for prices' and obtaining information through suppliers or customers, without any legal, ethical, or consent boundaries. This can facilitate social engineering, fraud, privacy violations, and improper acquisition of confidential business information in a way that goes beyond legitimate competitive research.

Ssd 4

Medium
Confidence
96% confidence
Finding
The skill presents a progression from public sources to semi-public and frontline human intelligence channels, culminating in deceptive pretexting ('pretend to be a customer') and informal human-source elicitation. In context, this operationalizes social-engineering-style collection against competitors and third parties, making misuse more likely than a neutral market-research template would.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.