Back to skill

Security audit

Bid Compliance Due Diligence V2

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed procurement-compliance due diligence helper that uses public web and knowledge-base searches, with no executable install behavior or persistence.

Install this only if you want agents to perform public-source procurement and bidding-compliance checks on companies. Be aware that broad prompts about whether a supplier is reliable may activate it, and its default related-party check may search the legal representative and largest shareholder for public招投标 risk signals. Review important conclusions manually before using them for business decisions.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are very broad and map to common, everyday due-diligence requests such as checking whether a company is reliable or has compliance issues. In an agent environment, this can cause the skill to activate for loosely related enterprise queries, expanding access to web retrieval and compliance analysis beyond narrowly scoped procurement-risk use cases.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrases are overly broad and include generic requests about whether a company is 'reliable' or 'can be used,' which can cause the skill to activate for ordinary reputation, procurement, or business-screening requests beyond narrowly scoped bid-compliance due diligence. In this skill’s context, broad activation is risky because it drives web-based collection and structured negative profiling of organizations, increasing the chance of overcollection, misclassification, or use in adversarial competitor intelligence workflows despite the stated guardrails.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.