Back to skill

Security audit

park-investment-report

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent report-generation helper that uses public/business data sources and writes an HTML report to a disclosed session path.

Before installing, be aware that using this skill will likely perform web searches, may call PatSnap-style enterprise data tools if available, may load Chart.js from a CDN in the generated report, and will create an HTML report file in the session reports directory. Check generated business data before relying on it for decisions, especially items the skill itself marks as medium or low confidence.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
91% confidence
Finding
The skill instructs the agent to write a standalone HTML file to a session path and specifies versioned filenames, but it does not require explicit user consent before creating or overwriting files. This can lead to unintended file creation, silent overwrite of prior report versions, or confusion about where artifacts are stored, especially in agent environments that persist session outputs.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.