Back to skill

Security audit

投标否决雷区体检Bid Rejection Minefield Checker

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed procurement-risk report generator that uses scoped knowledge-base lookups and optional user-provided documents, with no hidden execution or automatic data collection found.

Before installing or using this skill, avoid submitting confidential bid materials through the public feedback channel unless you have permission and can redact sensitive company, contact, pricing, and bid-document details. Uploaded/current project documents are expected for the core risk-check workflow, so users should treat them as sensitive procurement data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The README explicitly invites users to submit 'misjudgment cases' plus attachments for reuse in continuous improvement, but it does not describe what data may be included, how personal or confidential bidding materials will be handled, whether consent is required, or how long submissions are retained. In a procurement context, attachments may contain company identifiers, contact details, bid documents, or other sensitive commercial data, so silent collection/reuse creates a real privacy and data-governance risk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.