Back to skill

Security audit

爱图表 智能图表

Security checks across malware telemetry and agentic risk

Overview

This appears to be a real AI chart integration, but it asks for a persistent API key, sends user data to a third-party service, and bundles broader API powers than chart generation needs.

Review before installing. Use it only if you trust aitubiao with your API key and the chart data you provide, avoid sensitive or regulated datasets unless approved, and consider deleting or revoking the stored API key after use. Be careful with export paths so downloaded files do not overwrite important local files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The CLI exposes capabilities well beyond the manifest's stated chart-generation scope, including PPT creation, 3D illustration generation, quota inspection, snapshot-job querying, and arbitrary project export/download. This scope mismatch is dangerous because an agent or user may invoke unintended privileged actions not disclosed by the skill description, undermining least-privilege expectations and increasing the attack surface.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The download workflow writes server-returned content to a caller-supplied local path after only basic directory writability checks. In an agent context, this enables arbitrary file placement within any writable location, which can overwrite user files, drop misleading content, or stage follow-on abuse if the agent is tricked into choosing sensitive paths.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger phrases include broad, common requests such as 'create chart', 'make a chart', and generic chart type names, which can cause the skill to activate in situations where the user did not intend to use this third-party service. Because activation can lead to credential solicitation and remote data transmission, overbroad triggers meaningfully increase the chance of accidental exposure.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill handles user-supplied tables/files and sends structured data to `api.aitubiao.com`, but the description does not clearly warn users that uploaded content will leave the local environment and be processed by a remote third-party service. This is dangerous because users may unknowingly submit sensitive business, personal, or regulated data under the assumption that charting is local or first-party.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.