Back to skill

Security audit

投标模拟评标 · 评标表逆向工程Bid Mock Evaluation 1.0.0

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed bid-document analysis helper that reads user-provided procurement materials and optionally runs a local parser, with no evidence of hidden data sharing or destructive behavior.

Install only if you are comfortable providing bid documents or evaluation tables to the agent running this skill. Prefer specifying A, B, or C mode explicitly, keep inputs limited to the relevant project files, and review any legal or procurement compliance conclusions with current official sources or counsel.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
78% confidence
Finding
The skill instructs the agent to read local input files and produce derived outputs such as structured extraction results, but no permissions are explicitly declared. In a capability-gated environment, this mismatch can cause the agent to access files in ways users or operators did not expect, weakening auditability and increasing the chance of unintended data exposure from uploaded bid documents or related local files.

Vague Triggers

Medium
Confidence
74% confidence
Finding
When the user does not specify a mode, the skill automatically defaults to mode A and proceeds with substantive analysis. Overly broad default activation can lead to processing more material than the user intended, especially in a document-heavy workflow involving bid responses, and may trigger unnecessary handling of sensitive commercial information.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.