Back to skill

Security audit

bid-objection-reply-advisor

Security checks across malware telemetry and agentic risk

Overview

This is a domain-specific bidding-objection reply assistant with disclosed legal/compliance workflow and no hidden install, persistence, or data-exfiltration behavior.

Before installing, treat outputs as legal/compliance drafts rather than final advice. Provide only documents needed for the objection response, verify the applicable jurisdiction/platform rules, and have legal or procurement staff review any reply before sending it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
README 的“提问示例”使用了“帮我起草这份异议的答复”“这个异议成立不成立”等宽泛自然语言,没有限定必须在招投标异议答复场景下触发,也未给出负例或更明确的调用边界。这类短语与普通办公咨询高度重叠,可能造成误触发。

Natural-Language Policy Violations

Low
Confidence
80% confidence
Finding
Line L172 says the skill has explicitly standardized '3日' as calendar days, with only a fallback note if local platform rules differ. This imposes a default locale/jurisdiction interpretation rather than offering the user a clear upfront choice, which can be a natural-language locale policy concern.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.