Back to skill

Security audit

Lingxi

Security checks across malware telemetry and agentic risk

Overview

The skill is a broad autonomous AI orchestration system with credentials, memory, dashboards, and publishing workflows, but its scope and privacy boundaries are not clearly or consistently disclosed.

Review carefully before installing. Keep the dashboard local unless you add strong access controls, avoid passing tokens in URLs, use least-privilege credentials, and require manual approval before publishing, messaging, pushing to GitHub, changing skills, or using account-linked tools. Treat memories and task logs as sensitive user data and define retention and deletion rules before use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

High
Confidence
95% confidence
Finding
The README presents the skill as a 'shrimp-breeding assistant' while the rest of the document describes a broad AI orchestration platform with dashboard, memory, database, routing, external integrations, and multi-agent behavior. This kind of identity mismatch is dangerous because it can mislead reviewers and users about the actual scope, permissions, and risk surface of the skill, causing underestimation of sensitive capabilities.

Intent-Code Divergence

Medium
Confidence
93% confidence
Finding
The skill makes strong transparency and privacy assurances ('no hidden network requests' and 'no privacy collection') while elsewhere documenting external-channel integration and broad web-search/tool dispatch. Such contradictory claims can mislead operators and users about data flows, consent boundaries, and audit expectations, increasing the risk of unsafe deployment or oversharing sensitive inputs.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The '一句话,全自动' positioning describes very broad autonomous handling of user requests without concrete scope limits, approval gates, or disallowed-action boundaries. In a multi-agent orchestrator, this can cause over-invocation, unintended tool use, or execution of sensitive multi-step actions from vague prompts.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The top-level description promises automatic intent understanding and model/skill/tool orchestration but does not state when the skill should or should not activate. Without narrow routing criteria, normal user requests may be captured too broadly, causing unnecessary delegation, unexpected network/tool use, and expansion of the attack surface.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.