Market Analysis Cn

Security checks across malware telemetry and agentic risk

Overview

This is a small, instruction-only paid market-analysis skill with disclosed pricing and no executable code or hidden privileged behavior.

Install this only if you want a paid market-analysis assistant. Because the trigger list is broad, review when it activates and avoid sending confidential business, customer, or competitor data unless you are comfortable sharing it for analysis.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
97% confidence
Finding
The trigger list includes very broad terms such as '市场分析', '竞品分析', 'market analysis', and especially '趋势', which are likely to appear in ordinary user conversation outside the intended paid skill flow. This can cause over-triggering, unexpected skill invocation, and routing of unrelated user requests into a commercial service, creating confusion and potential abuse of the agent’s skill-selection behavior.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal