室内设计自动预算生成器

Security checks across malware telemetry and agentic risk

Overview

This skill locally converts a user-supplied interior-design DXF into an Excel budget, with no evidence of hidden network access, credential use, or destructive behavior.

Before installing, confirm the hard-coded budget library path matches your machine and review that JSON because generated spreadsheets can expose internal pricing assumptions. Run it only on DXF files you intend to process, and choose an output path where replacing an existing spreadsheet would be acceptable.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrases are generic budget-related terms such as '生成预算' and '预算自动生成', which can easily match ordinary user requests outside the narrow interior-design DXF workflow. This can cause unintended skill activation, leading the agent to route unrelated budgeting tasks into this skill and produce incorrect outputs or expose users to unintended file-processing behavior.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal