Back to skill

Security audit

招标文件萝卜坑识别专家(投标人版)Bid Carrot Pit 1.0.0

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed procurement-document review aid, but users should verify its legal citations because some examples conflict with its own citation rules.

Before relying on this skill for a real procurement dispute, independently verify the project type and every legal citation, especially whether government procurement and tendering/bidding law references are being mixed. Treat its output as drafting support, not legal advice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The report states a strict rule that government procurement projects must not cite the Tendering and Bidding Law system, but the very next example text does exactly that. This contradiction can cause users to submit legally misframed objections or complaints, undermining credibility and potentially harming their procedural position. In a legal-guidance skill, internal inconsistency is more dangerous because users may rely on the generated text as compliance-sensitive output.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.