1coos-calendar-cn

Security checks across malware telemetry and agentic risk

Overview

This appears to be a local Chinese calendar lookup skill with no evidence of networking, credential access, persistence, or hidden side effects.

Reasonable to install if you want a Bun-based local Chinese calendar and almanac tool. Be aware it may activate for a broad range of Chinese calendar-related questions, and only use non-sensitive config files when passing --config.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger description is very broad, covering many common Chinese calendar and astrology-related terms without defining tighter activation boundaries. This can cause the skill to be invoked in contexts where the user did not intend to run it, increasing the chance of incorrect tool routing, unnecessary local code execution, or accidental exposure to outputs from a skill that accepts user-controlled arguments such as --config.

VirusTotal

67/67 vendors flagged this skill as clean.

View on VirusTotal