Back to skill

Security audit

政采政策红利自检助手(投标人版)Bid Policy Checker

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Chinese government-procurement self-check assistant with no executable install behavior or hidden data handling found.

Installers should understand this skill is intended for Chinese government-procurement scenarios and may not be useful outside that legal and language context. Do not upload unrelated confidential documents; use it as an auxiliary policy-checking tool and verify final conclusions against original procurement documents or legal counsel.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Natural-Language Policy Violations

Low
Confidence
92% confidence
Finding
The README presents all user-facing skill description content exclusively in Chinese and does not mention that the skill is Chinese-only or offer an alternative language option. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern unless the locale constraint is explicitly documented and justified.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The skill name, title, and style guidance are all specified in Chinese, including an explicit requirement for a colloquial explanatory style aimed at Chinese-speaking bidders. Because the file does not offer any language or locale choice, it imposes a specific language experience by default, which matches the language/locale policy violation criteria.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The manifest presents the skill entirely in Chinese, including the display name, description, changelog, and feedback note, with no indication that users can choose another language or that the language restriction is region-specific. Per the policy, a skill should not implicitly force a specific language unless it is clearly documented and justified or offers user opt-in.

Natural-Language Policy Violations

Low
Confidence
94% confidence
Finding
This markdown file contains natural-language instructions and test cases only in Chinese, and there is no visible opt-in, alternative locale, or justification that the skill is intentionally limited to a Chinese-language/regional context. Under the policy rule for language/locale, forcing a specific language without user choice can be a policy concern.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.