Back to skill

Security audit

Kl8 Data

Security checks across malware telemetry and agentic risk

Overview

This skill is a simple local KL8 lottery data helper, but its README contains unrelated Bilibili notes that should be cleaned up.

Before installing, understand that this uses stale hardcoded March-April 2026 KL8 data and will not fetch current results. The publisher should remove the unrelated Bilibili notes and narrow the trigger phrases, but the reviewed files do not show credential access, persistence, destructive actions, or data exfiltration.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The skill is documented as a narrowly scoped KL8 lottery data utility, but the markdown includes unrelated Bilibili learning/history entries, device/data-access topics, opaque UUID-like strings, and external links. This breaks scope integrity and can mislead downstream agents or users into treating irrelevant or potentially adversarial content as trusted skill metadata, increasing prompt-injection and unintended routing risk.

Vague Triggers

Medium
Confidence
81% confidence
Finding
The trigger phrases are broad enough to match common lottery-related terms such as '福彩' or '开奖数据', which can cause the skill to activate outside its intended KL8-specific context. Overbroad invocation increases the chance that the agent routes unrelated user requests into this skill, exposing users to incorrect outputs and increasing the attack surface for any embedded malicious or irrelevant content.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.