Back to skill

Security audit

gov-doc-skill

Security checks across malware telemetry and agentic risk

Overview

The skill is a non-executable government document drafting assistant, but it under-warns users while asking for potentially sensitive or classified government materials.

Install only if you intend to draft Chinese government-style documents and can control what information is submitted. Do not provide classified, internal-only, personal, unpublished, or legally restricted government material unless your organization has approved the AI environment and retention rules. Prefer anonymized summaries and placeholders, and require human policy, legal, and confidentiality review before official use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The README explicitly encourages users to upload detailed government materials such as internal work progress, problem lists, superior instructions, draft documents, and sensitive constraints, but provides no warning about confidentiality, classification, personal data, or whether such content may be sent to third-party AI services. In a government-document drafting context, this materially increases the likelihood of exposing non-public, sensitive, or classified information to the model or platform.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.