Ai工作流 43de14

Security checks across malware telemetry and agentic risk

Overview

This appears to be a markdown guidance skill with broad activation wording, not malware or a privileged integration.

Install only if you are comfortable with a general AI workflow/Coze helper that may be invoked by broad keywords. The publisher should narrow the triggers, but the available evidence and clean VirusTotal telemetry do not justify Review or malicious classification.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger scenarios are broad and based on generic phrases like 'AI工作流' and '2026Coze', which can cause the skill to activate in many unrelated conversations. Overbroad invocation increases the chance of unintended routing, prompt/context pollution, and user confusion, especially in environments with multiple overlapping skills.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The manifest trigger field is populated with broad keywords instead of precise activation phrases, making accidental invocation likely. In a skill ecosystem, this can cause the wrong skill to claim requests, leading to misexecution, reduced trust, and possible exposure of irrelevant or stale workflow guidance.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal