Back to skill

Security audit

本地生活门店诊断+口播文案+获客复盘(老板自助)

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly a local-business marketing assistant, but it needs review because it says diagnostic data stays local while also directing users to external feedback and hosted diagnostic pages.

Before installing, treat this as a business-data advisor that may ask for sales, livestream, customer-retention, and backend performance details. Use the local workflow for sensitive data, avoid entering customer personal information or confidential figures into the linked Notion or hosted diagnostic pages unless you are comfortable sharing it with those services, and ask the publisher to clarify remote data handling and where any recorded predictions are stored.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Description-Behavior Mismatch

Medium
Confidence
86% confidence
Finding
The skill states that diagnosis/reporting stays local, yet it also instructs users to use external feedback pages and remote diagnostic pages. This creates a misleading privacy representation: users may disclose business or operational data believing it remains local when the workflow nudges them toward third-party services.

Intent-Code Divergence

Medium
Confidence
89% confidence
Finding
The document explicitly claims diagnostic data only exists locally, but elsewhere offers remote feedback and hosted diagnostic tools. Even if uploads are optional, the contradiction can cause users to reveal potentially sensitive store data under false assumptions about data handling.

Description-Behavior Mismatch

Medium
Confidence
79% confidence
Finding
The skill introduces WeChat CRM, customer database accumulation, and direct customer reach workflows outside the parent skill’s declared modes, creating risk of collecting, retaining, or operationalizing customer data without explicit consent, minimization, or compliance controls. In an agent context, expanding into private-domain customer management increases the chance that users will be guided to handle personal data in ways that violate privacy expectations or platform/legal requirements.

Vague Triggers

Medium
Confidence
80% confidence
Finding
The trigger phrases are broad conversational phrases such as asking for diagnosis or help with a store, which can overlap with normal user requests. This increases the chance of accidental activation or mode switching, causing unintended behavior and unplanned disclosure of business details into the skill workflow.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The routing rules map common phrases like 'data', 'review', or 'how to do' to different modes without clear disambiguation boundaries. Ambiguous routing can send user input into the wrong workflow, leading to irrelevant prompts, accidental context carryover, or overcollection of business information.

Vague Triggers

Low
Confidence
72% confidence
Finding
The fallback trigger phrase '不会用'/'卡住了' is vague and could be said casually during normal conversation. While lower impact than broad primary triggers, it can still unexpectedly switch the assistant into exception-handling behavior and disrupt the intended interaction.

Skill Enumeration

Medium
Category
Agent Snooping
Content
> 激活后,直接说「帮我诊断门店」就能用。

**安装路径确认:**
- WorkBuddy: `~/.codebuddy/skills/local-business-live-cycle/SKILL.md`
- Hermes: `~/.hermes/profiles/deepseek-v4/skills/consulting/local-business-live-cycle/SKILL.md`
- SkillHub 安装: `skillhub install local-business-live-cycle`
Confidence
90% confidence
Finding
skills/local-business-live-cycle/SKILL.md

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.