Back to skill

Security audit

company-tech-profile

Security checks across malware telemetry and agentic risk

Overview

This skill is a public-research workflow for company technology reports, with no hidden code, persistence, credential handling, or destructive behavior found.

Before installing, be aware that the skill may proceed with public research and local report-file creation when given a company and technology area, and may infer a likely topic from a company-only request. Users who need stricter control should specify the company, topic, time window, and decision purpose explicitly.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill description and invocation guidance are broad enough that an agent may select this skill for loosely related company-plus-technology mentions even when the user did not clearly request a technical profiling workflow. That can cause scope overreach, unnecessary external research, and unintended file/tool actions, especially in agent runtimes that automatically route to skills based on description matching.

Vague Triggers

Medium
Confidence
93% confidence
Finding
Allowing the skill to infer a technology topic from a company-only prompt creates ambiguous activation and lets the agent make unstated assumptions about user intent. In practice, this can trigger research and report generation for a topic the user did not request, increasing the risk of privacy, compliance, or workflow misuse in autonomous environments.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.