Back to skill

Security audit

Bid Doc Reviewe 2.0.0

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed bid-document compliance review assistant with no executable code or hidden system access.

Before installing, treat the output as compliance assistance rather than formal legal advice, verify cited rules against current local regulations, and provide project type, funding source, tender body, method, estimated value, and jurisdiction so the skill stays within scope.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger list contains broad natural-language phrases such as '招标文件有没有问题' and '品牌要求合规吗', which are likely to match ordinary user requests beyond the intended scoped workflow. This can cause unintended invocation of the skill in contexts where the required gating information, legal scope boundaries, or exclusions are not established, increasing the chance of misrouting sensitive compliance questions and producing overconfident legal-review output.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.