Back to skill

Security audit

标书查重专家Bid Dup Check

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed bid-document duplicate-checking helper that processes user-supplied files locally in the session and generates reports, with some privacy and branding points users should understand.

Before installing, confirm that users are allowed to process the bid documents in this environment and redact unnecessary personal, bank, or commercial secrets where possible. Review generated reports before sharing them formally because they include a fixed author/feedback footer and may contain extracted sensitive fields or document metadata needed for the analysis.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Context-Inappropriate Capability

Medium
Confidence
86% confidence
Finding
The renderer injects fixed personal branding and an external feedback/contact channel into every generated report, regardless of user intent or organizational policy. In procurement or compliance workflows, this can leak users toward off-platform contact, create unauthorized endorsement, and introduce unapproved content into formal artifacts.

Context-Inappropriate Capability

Medium
Confidence
86% confidence
Finding
The Markdown renderer repeats the same fixed branding and external contact insertion, causing all exported text reports to carry unrelated promotional or off-platform communication content. This is risky in sensitive bidding workflows because generated reports may be redistributed as official screening artifacts and the injected footer is not part of the declared duplicate-checking function.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The README instructs users to upload multiple bid or tender documents, which commonly contain sensitive commercial, personal, and account information, but it does not clearly warn about privacy, retention, third-party processing, or data handling boundaries. In a procurement context, this omission can lead users to disclose confidential bidding materials without informed consent, increasing the risk of unauthorized exposure or compliance violations.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.