Back to skill

Security audit

Requirement Assessment

Security checks across malware telemetry and agentic risk

Overview

This skill openly helps turn project requirements into a Feishu Bitable estimate, with privacy considerations but no hidden or malicious behavior found.

Install this only if you want the agent to create Feishu Bitable records for requirement assessments. Before use, confirm the destination workspace and sharing permissions, and redact secrets, customer confidential data, regulated personal data, budgets, or internal technical details that should not be stored in Feishu.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly instructs the agent to take user-provided requirements and create Feishu Bitable records, but it does not require a privacy notice, user confirmation of external sharing, or data-minimization before transmission. Because requirements often contain client names, business plans, internal system details, or regulated data, this can cause unintended disclosure to a third-party SaaS workspace.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal