Back to skill

Security audit

bid-rejection-risk-radar

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent bid-document risk checklist helper, with no evidence of hidden execution, credential access, or unrelated data handling.

Install only if you want an assistant to analyze procurement or tender documents for rejection-risk checklists. Because those documents can contain sensitive business information, confirm the skill is intentionally invoked before uploading files and review any knowledge-base/legal anchoring results manually.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger list includes broad natural-language phrases such as “风险雷达”, “这个标能不能投”, and “资格审查能不能过”, which can plausibly appear in ordinary conversation and may cause the skill to activate outside the user's intended scope. In this skill’s context, accidental invocation could route sensitive procurement documents into a specialized analysis flow unexpectedly, creating reliability and possible data-handling risks even though the content is not overtly malicious.

VirusTotal

38/38 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.