行业分析·HTML 渲染

Security checks across malware telemetry and agentic risk

Overview

This skill is a scoped report-rendering helper that reads known input files, writes a disclosed HTML output, and updates pipeline status.

Install this if you want an agent to convert an existing industry analysis workspace into a visual HTML report. Before running it, check whether output/{industry-slug}/industry-analysis-report.html already exists, because reruns may overwrite that file and update output/{industry-slug}/session.json.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly instructs the agent to write `industry-analysis-report.html` and update `session.json`, but it does not require confirming file modifications with the user or clearly warning that local files will be changed. In an agent environment, silent writes can overwrite prior outputs, alter workflow state, and create unexpected persistence on disk, especially when the skill is invoked as part of an automated pipeline.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal