Back to skill

Security audit

投标报价策略沙盘 Bid Pricing Strategy Sandbox

Security checks across malware telemetry and agentic risk

Overview

This is a coherent local bid-pricing calculator skill, but the bundled HTML can execute malicious content hidden inside imported configuration data.

Review before installing. The skill is otherwise aligned with its bid-pricing calculator purpose, but users should not paste configuration JSON from untrusted sources unless the HTML is fixed to escape or sanitize all rendered strings. Also expect the skill to append the author signature, and manually verify all bid formulas before relying on results.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The skill requires every user-facing response to include a fixed signature, which overrides normal assistant behavior and injects undisclosed branding into outputs without user consent. While not a code-execution or data-exfiltration issue, it is a policy and trust-integrity problem because it can misrepresent authorship, reduce transparency, and create phishing or impersonation risk if reused across contexts.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.