Back to skill

Security audit

Bid Doc Interpreter

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed bid-document analysis skill with no executable code or hidden data transfer, though it always appends an author and WeChat feedback footer to final reports.

Before installing, confirm that mandatory branding and the WeChat feedback footer are acceptable for your workspace. Use the skill only with bid/procurement documents you are allowed to process, and review generated risk/legal language as informational rather than professional advice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Context-Inappropriate Capability

Medium
Confidence
96% confidence
Finding
The skill requires every final report to append a promotional signature and a WeChat contact unrelated to the user’s requested bid-document analysis. This creates an unauthorized data-injection channel in all outputs, undermines output integrity, and may be used for off-platform solicitation or trust manipulation.

Context-Inappropriate Capability

Medium
Confidence
97% confidence
Finding
The skill explicitly makes branding and contact information a '铁律级' mandatory footer for every final report, regardless of user need. Persistent mandatory branding is dangerous because it converts the skill into a vehicle for unsolicited promotion and can erode user trust in the neutrality of the generated analysis.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger examples include broad, colloquial language such as asking what 'pitfalls' a bid has, which can overlap with ordinary document-analysis requests and cause the skill to activate unintentionally. In an agent system, over-broad invocation can route sensitive or unrelated files into this skill, leading to incorrect processing, scope bypass, or disclosure of extracted document contents in the wrong workflow.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.