Back to skill

Security audit

茶不二

Security checks across malware telemetry and agentic risk

Overview

This is a coherent Xiaohongshu marketing skill, but it needs review because it encourages child vision-data sharing and under-specifies external knowledge-base use for health-related content.

Install only if you are comfortable using it for health-adjacent marketing content. Before using it publicly, remove prompts that ask parents to post children's ages, exam numbers, or reports in comments, add privacy-preserving intake language, and require explicit approval before any optional IMA or external knowledge-base lookup is used.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill explicitly tells installers to configure IMA credentials and later uses those credentials to retrieve external knowledge without any clear runtime disclosure to the end user. This creates a privacy and consent risk because user prompts or sensitive context related to medical topics could be sent to an external knowledge base unexpectedly.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The workflow automatically triggers searches of external knowledge-base skills for myopia-related topics, but does not require notice or consent at the time of retrieval. In a health-related skill, that can expose sensitive user questions, medical details, or case context to external systems without transparency, increasing privacy and compliance risk.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The activation description is broad enough to trigger on generic writing, optimization, planning, and analysis requests, which can cause this skill to activate outside its intended narrow domain. Because the skill carries strong persona, workflow, and tool-calling instructions, unintended activation could override user preferences, apply brand-specific guidance in irrelevant contexts, or invoke specialized sub-skills unnecessarily.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The skill strongly fixes the interaction to a Chinese-language persona and output style without checking the user's language or consent. If activated for users expecting another language or neutral tone, it can silently override user intent, reduce usability, and increase the chance of misleading or inappropriate outputs due to forced persona framing.

Ssd 3

Medium
Confidence
93% confidence
Finding
The skill encourages calls to action such as asking users to post numbers, ages, reports, or send data for analysis in comments or direct messages. In a health-related context involving children and vision reports, this can prompt unnecessary collection and public disclosure of sensitive personal and quasi-medical information, increasing privacy, compliance, and misuse risks.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.