Mini Crm

Security checks across malware telemetry and agentic risk

Overview

This is a simple CRM instruction skill that may process customer contact and sales data, but its behavior is disclosed, purpose-aligned, and not technically overreaching.

Install only if you intend to use it for customer management. Use it with customer data you are authorized to process, store records in an access-controlled location, avoid collecting unnecessary identifiers, and redact contact or financial details before sharing generated reports.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly handles customer personal and business data, including names, WeChat IDs, email addresses, budgets, contact history, and deal status, yet it provides no privacy warning, consent guidance, retention limits, or notice that outputs may expose sensitive records. In a CRM context, this increases the risk of unauthorized collection, disclosure, or mishandling of personal data through normal use of the skill.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal