法眼·AI合同审查

Security checks across malware telemetry and agentic risk

Overview

This paid contract-review skill is mostly coherent, but it sends full legal contract text to an external service without enough privacy disclosure.

Review before installing. Use this only for contracts you are authorized to send to ai-gaoqian.xyz, and avoid highly confidential or regulated documents unless the publisher provides clear retention, storage, operator, and security terms. Confirm any Alipay payment prompt and expected ¥0.50 charge before proceeding.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs users to upload full contract text and send it to an external endpoint (`https://ai-gaoqian.xyz/review`) but does not clearly warn that potentially sensitive legal documents are transmitted off-platform to a third-party service. Because contracts commonly contain confidential business, personal, and financial data, this omission can cause users to disclose sensitive information without informed consent, creating privacy, confidentiality, and compliance risk.

VirusTotal

55/55 vendors flagged this skill as clean.

View on VirusTotal