Back to skill

Security audit

AI Decision Coach - 决策教练

Security checks across malware telemetry and agentic risk

Overview

This is a simple Chinese decision-coaching prompt with no code, data access, install scripts, or privileged actions.

Safe to install from a security perspective. Treat it as general decision support, not professional legal, medical, financial, or crisis advice; be aware it may activate on broad indecision language and is primarily written for Chinese interactions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill activates on very broad signals like general indecision or hesitation, which can cause it to take over ordinary conversations that were not intended as structured decision support. Over-broad activation increases the chance of scope hijacking, irrelevant intervention, and unintended steering of sensitive user choices without clear user consent.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
Forcing Chinese output regardless of the user's language can cause misunderstanding of advice, incorrect interpretation of risks, and degraded usability in consequential decisions. In a decision-support skill, language mismatch can materially affect comprehension of tradeoffs and next steps, especially when the discussion involves nuanced or high-stakes choices.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.