Back to skill

Security audit

建筑规范转Skill (code-to-skill)

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent building-regulation PDF-to-skill workflow with disclosed local file processing and user confirmations, though users should verify the helper tool path before running it.

Before installing, confirm you intend to process building-code or regulation PDFs and only approve execution of book-to-skill tools from a trusted local installation path. Review generated files for legal wording accuracy before relying on them for professional work.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
82% confidence
Finding
The manifest description contains very broad activation phrases such as generic requests to make a skill or build a knowledge base, which could cause the skill to trigger on ordinary user requests outside the intended building-code domain. Over-broad invocation increases the chance of unintended tool use, file handling, or workflow execution on unrelated content.

Vague Triggers

Low
Confidence
74% confidence
Finding
The mode activation logic relies on loosely defined natural-language cues like 'analyze' or '先分析' without a strict scoping rule, so an agent may enter a mode based on incidental wording rather than explicit user intent. This ambiguity can lead to incorrect workflow branching and accidental processing behavior, though the security impact is limited compared with direct code execution issues.

Hidden Instructions

High
Category
Prompt Injection
Content
tags: ["建筑设计", "建筑设计规范", "建筑规范", "建筑", "规范", "国家标准", "GB标准", "防火规范", "条文", "工程", "building-code", "GB-standards", "regulation", "fire-protection", "code-to-skill", "法规", "审图", "结构设计", "GB50016"]
---

<!--
Cross-agent notes (informational; ignored by host agents):
  - Compatible skill roots: OpenClaw (<workspace>/skills/),
    GitHub Copilot CLI (~/.copilot/skills, ~/.agents/skills),
Confidence
88% confidence
Finding
<!-- Cross-agent notes (informational; ignored by host agents): - Compatible skill roots: OpenClaw (<workspace>/skills/), GitHub Copilot CLI (~/.copilot/skills, ~/.agents/skills), Claude Cod

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.