Ai Intelligent Customer Segmentation

Security checks across malware telemetry and agentic risk

Overview

This skill is a simple customer-segmentation description with disclosed install steps, but users should review the external code and handle customer data carefully.

Before installing, review the linked GitHub repository, requirements.txt, and app.py in an isolated environment. Because this tool may be used with customer or CRM data, verify consent, access controls, retention limits, and privacy/marketing-law compliance before using it on real customer records.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill explicitly promotes customer segmentation, profiling, and targeted marketing, but provides no notice about personal data handling, consent, retention, or privacy impact. In a customer-data context, this omission can enable unsafe deployment that processes identifiable behavioral or transactional data without adequate transparency or safeguards, increasing privacy, compliance, and misuse risk.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal