Back to skill

Security audit

短视频数据引擎 | 青虎AI

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed paid Qinghu workflow for collecting short-video metrics and exporting a spreadsheet, with clear confirmation requirements before spending credits.

Before installing, expect to provide a Qinghu API key, send the listed video URLs to Qinghu, and approve a quoted credit cost before any paid task is submitted. Use only authorized video links and review any qhkit/Node installation prompts because they modify the local environment.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The description says the skill 'must' trigger for broad classes of requests like video data statistics and competitor monitoring, without clear exclusions or precedence rules. This can cause over-activation and tool invocation on loosely related user queries, increasing the chance of unnecessary external actions, billing exposure, and context hijacking by a third-party workflow.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example trigger phrases are common user utterances that overlap with ordinary analytics or comparison requests. In an agent routing system, this ambiguity can misroute benign requests into a paid external data collection workflow, causing unintended tool use, privacy leakage of supplied links, or unnecessary charges.

Natural-Language Policy Violations

Low
Confidence
83% confidence
Finding
Instructing the agent to relay CLI messages verbatim and treating them as user-facing Chinese can override the user's language preference and blindly trust external tool output. While not directly code-execution, it creates an output-injection surface where tool-controlled text may be surfaced without translation, sanitization, or contextual filtering.

Natural-Language Policy Violations

Low
Confidence
79% confidence
Finding
The failure-handling guidance assumes Chinese-only communication, which can conflict with user preferences and system-wide localization rules. This is primarily a quality and policy-routing issue, but it can still degrade trust and make phishing-like or misleading external messages harder for some users to evaluate.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.