Back to skill

Security audit

Tmp.NoCba5uMqw

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly a legitimate local-business marketing assistant, but it needs review because it under-discloses remote links, local report files, and broad bundled marketing guidance.

Install only if you are comfortable with a marketing assistant that may create local diagnostic report files, open or reference external Notion/GitHub/CDN pages, and include broad marketing playbooks beyond the core local-store workflow. Before using it with real merchant or customer data, confirm where reports will be saved, avoid sending sensitive screenshots to WeChat/Notion unless intended, and review any externally hosted diagnostic page separately.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (19)

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The skill states that diagnostic data remains local, but it also directs users to external Notion, GitHub Pages, and CDN endpoints for feedback and remote tool usage. This creates a privacy and trust mismatch: users may disclose business or operational data believing it stays local when the workflow explicitly encourages leaving the local environment.

Intent-Code Divergence

Low
Confidence
84% confidence
Finding
The document says the consultant manual is 'not externally open' while earlier instructions tell the agent to load it directly with skill_view. That inconsistency can cause unauthorized access to supposedly internal guidance, and may expose pricing logic, playbooks, or sensitive business processes to users or downstream agents.

Context-Inappropriate Capability

Low
Confidence
96% confidence
Finding
The skill includes author biography, social links, and direct solicitation for paid groups/consulting that are unrelated to the core task of generating short-video scripts. This creates unnecessary off-platform redirection and trust-manipulation risk, and may pressure users to disclose information or engage outside the monitored environment.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The file defines a broad generic content creator persona spanning SEO, Twitter, B站, and long-form content production, which does not align with the declared skill purpose of a local-business live-operations assistant focused on store diagnosis, livestream prep, and review. This scope mismatch can cause the agent to operate outside user expectations, produce irrelevant or unsafe outputs for the advertised workflow, and weaken policy boundaries by importing unrelated behaviors into a business-operations skill.

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The file’s behavior and domain are materially different from the declared skill purpose: it is a knowledge-payment product strategist embedded inside a local-business live-ops assistant. This kind of scope mismatch can cause the agent to provide unintended guidance, route users into the wrong workflow, and bypass operator expectations or policy review that was based on the manifested skill description.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The file content does not match the declared skill metadata: it defines a WeCom private-domain marketing operator instead of the advertised local-business live-cycle assistant with store diagnosis, short-video, live-stream preparation, and data review modes. This mismatch can cause the agent to invoke an unexpected capability set, leading to unsafe delegation, incorrect data handling expectations, and policy/control gaps because reviewers and users are assessing the wrong behavior.

Description-Behavior Mismatch

High
Confidence
92% confidence
Finding
This file materially expands the skill from local-business Douyin/live-stream operations into Xiaohongshu brand and influencer campaign management, which is outside the declared scope. Scope drift is dangerous because it can cause the agent to perform unexpected actions or provide guidance users and reviewers did not consent to, weakening trust boundaries and policy review assumptions.

Context-Inappropriate Capability

Medium
Confidence
87% confidence
Finding
The content includes influencer/KOL/KOC screening, seeding, and campaign planning capabilities that are not justified by a local-store live-operation assistant focused on Douyin/live streaming. Even if not overtly malicious, these hidden or extra marketing capabilities increase misuse risk, enabling undisclosed promotional operations and broader campaign execution than the skill description suggests.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The manual instructs the agent to create local HTML/PDF artifacts and save them to the user's desktop, which expands behavior from advisory conversation into local file-system side effects. Even if intended for convenience, undisclosed file creation can surprise users, expose sensitive business data on disk, and be abused to overwrite or proliferate files outside the expected assistant scope.

Description-Behavior Mismatch

Medium
Confidence
89% confidence
Finding
The version history adds a remotely hosted diagnostic tool delivered from an external CDN/GitHub Pages URL, but this capability is not reflected in the public skill description. Undisclosed external delivery increases supply-chain and content-integrity risk because the hosted page can change independently of the reviewed skill content and may collect data or execute unexpected logic.

Context-Inappropriate Capability

Medium
Confidence
87% confidence
Finding
The manual directs use of headless Chrome to render local HTML into PDF, introducing execution of a browser process and active content rendering beyond simple text assistance. Rendering HTML with browser capabilities can amplify risk if any report content is attacker-controlled, enabling unexpected network access, script execution, or unsafe local processing paths.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
The template loads executable JavaScript from a third-party CDN, which creates a supply-chain and privacy risk: if the CDN content is modified, blocked, or replaced, arbitrary script will execute in the report context. Because this is a local business diagnosis/reporting template and not a web app that clearly requires remote dependencies, the external script is not strongly justified and increases exposure unnecessarily.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrases include broad everyday language such as '复盘', '数据', '效果怎么样', and '不会用', which can match normal conversation outside the user's intent to invoke this skill. Over-broad activation can unexpectedly reroute a session into the skill's workflow, causing unintended instruction precedence, data collection prompts, or external-link exposure.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The skill advertises one-utterance activation without defining clear scope boundaries, confirmation steps, or exclusions. In an agent environment, this increases the chance of accidental activation and unintended execution of embedded workflow logic based on ambiguous user input.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger list contains broad natural-language activators such as '帮我写个获客脚本' and '实体店怎么做短视频', which can overlap with ordinary user conversation and cause unintended invocation. Accidental activation can expose the skill in contexts where users did not explicitly request it, increasing the chance of irrelevant behavior or unsolicited guidance.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill repeatedly instructs users to enable precise location tagging to improve local reach, but provides no privacy or safety warning. Publishing geolocation can expose a business or individual operator's location patterns and may create physical safety, stalking, or doxxing risks, especially for small owner-operated shops.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The skill is explicitly scoped to Chinese e-commerce operations and its metadata/content are entirely in Chinese, which can cause the agent to respond in a fixed locale without checking the user's preferred language. This is primarily a quality and accessibility issue rather than a classic security flaw, but it can lead to misunderstanding, unsafe business actions, or poor user consent around language choice.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The instructions direct local file and PDF creation on the desktop without any user-facing warning or consent step. Silent persistence of potentially sensitive merchant diagnostics increases privacy and operational risk, especially on shared devices or environments where desktop files are synced, backed up, or accessible to other users.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The workflow explicitly instructs staff to collect customers on WeChat as part of redemption and retention without any notice about what data is being collected, why it is being collected, or how it will be used. In a customer-acquisition skill for local businesses, this omission is more dangerous because non-expert operators may copy the script directly into real-world campaigns, leading to undisclosed personal data collection and privacy/compliance violations.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.