Back to skill

Security audit

Chudaxia Ai Coach

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent enterprise AI training coach, with privacy and consent cautions around client research and recorded interviews.

Install only if you want an enterprise AI transformation coaching workflow. Before using it with real clients or employees, confirm permission for external company research, obtain consent before recording or transcribing interviews, minimize personal and confidential business data, and use only organization-approved tools for transcripts and knowledge bases.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
83% confidence
Finding
The trigger conditions are very broad and include common enterprise-AI terms such as AI培训, AI转型, 数字员工, and AI教练. This can cause the skill to activate in unrelated conversations, leading the agent to apply specialized instructions, personas, or downstream tool-calling behavior when the user did not intend it, which is a prompt-scope and control-boundary issue rather than direct code execution risk.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The workflow explicitly directs use of external search sources such as 企查查 and internet search to research clients, but provides no privacy, consent, data-minimization, or handling constraints. In a B2B consulting context, this may encourage collection, enrichment, or disclosure of sensitive company or personal information through third-party services without appropriate authorization or compliance review.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The interview guide explicitly recommends using recording or transcription tools during employee interviews, but it does not instruct the interviewer to notify participants, obtain consent, or follow applicable recording/privacy requirements. In an enterprise training context, these interviews may capture personal data, confidential business details, or employee statements, creating privacy, legal, and trust risks if recording is done without proper notice and authorization.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.