Back to skill

Security audit

直播复盘六部曲

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed livestream review checklist and does not add hidden code, credentials use, persistence, or broad system access.

Installers should understand this is an operational analysis template for Douyin e-commerce livestreams. It may be less applicable to other platforms or newer algorithm behavior, and users should avoid treating its benchmark numbers as authoritative without checking current platform data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are generic user utterances like '帮我分析一下' and '最近几场直播感觉不对劲', which are broad enough to match normal conversation outside a clearly scoped livestream post-mortem workflow. This can cause unintended invocation of the skill in contexts where the user did not explicitly request this methodology, leading to misrouting, irrelevant guidance, or unexpected access to adjacent operational logic.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.