Back to skill

Security audit

Bid Rejection Experience 1.0.3

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed question-answering skill for bid rejection and invalid-bid risk guidance, with no executable code, persistence, credential access, or write capability found.

Install only if you want Chinese-language bid rejection and invalid-bid risk Q&A that reads a public knowledge base and may use web search for current references. Treat its answers as informational, not legal advice, and expect a fixed attribution/disclaimer footer in responses.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger phrases are broad enough to capture general bidding or document-review requests beyond the skill's stated niche of bid rejection/invalid bid experience. In an agent routing context, this can cause misclassification and send users to a skill that may provide incomplete or inapplicable advice, creating reliability and compliance risk in a regulated procurement domain.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The skill mandates a fixed Chinese-language signature block in every final answer, regardless of the user's language or formatting preferences. While not a direct security exploit, this creates prompt-level policy override behavior that can interfere with host application UX, downstream parsers, or platform-level response controls, especially when output format must remain user- or system-governed.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.