Back to skill

Security audit

Bid Management

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward bid-document helper; the main caution is that bid files and generated outputs may contain confidential business information.

Install this if you need help organizing bid or tender documents. Treat uploaded tender files and generated bid outputs as confidential, keep files local by default, and explicitly verify any WeCom recipient, channel, and attachment contents before sending.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

High
Confidence
96% confidence
Finding
The skill states that outputs can be packaged and sent via WeCom, but it provides no data-handling guardrails for bid documents, which often contain confidential commercial, pricing, and procurement information. This creates a real risk of unintended external transmission, policy violations, and leakage of sensitive tender materials through an enterprise messaging channel.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.