AI News ZH - 中文AI科技日报

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed AI news digest workflow that fetches public news, summarizes it in Chinese, and can optionally send it to configured messaging channels.

Before installing or scheduling it, confirm which channel it can post to, run a manual preview first, use least-privilege search or messaging credentials, and make sure the cron job or channel configuration is easy to disable.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The manual trigger phrase is a generic natural-language request that closely matches ordinary user intents, so the skill may activate unexpectedly during normal conversation. Because this skill performs web collection and can lead into outbound push workflows, accidental invocation can cause unintended network activity, surprise automation, or downstream message delivery without clear user consent.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill advertises automatic delivery to Feishu, Telegram, and Discord, but it does not clearly warn users at invocation time that content may be transmitted to external services. In a conversational setting, this can cause users to unknowingly authorize outbound sharing, which is especially risky if summaries contain sensitive prompts, internal context, or organization-specific commentary.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal