fullask

Security checks across malware telemetry and agentic risk

Overview

This skill is a read-only logistics reporting helper that uses a specific dashboard and two named Excel files, with no evidence of hidden execution or harmful behavior.

Install only if the user is authorized to let an agent view the Jingwe logistics dashboard and read the named local spreadsheets. Confirm that 2.xlsx and 揽收及时率异常明细.xlsx are the intended files before use, and verify the fixed pickup-timeliness assumption before relying on the operational recommendations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill instructs the agent to read local Excel files ('2.xlsx' and '揽收及时率异常明细.xlsx') without any user-facing notice, consent, or constraint on what files may be accessed. In an agent environment, local file reads can expose sensitive business or personal data unexpectedly, especially when filenames are generic and may refer to broadly accessible local content.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal