Back to skill

Security audit

bidding-evaluation-expert

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed China bidding-law assistant with no executable code, persistence, or hidden local access.

Install only if you want PRC bidding-law evaluation support. Treat outputs as decision support, not formal legal advice, and avoid sending confidential tender or bid materials through external knowledge-base connectors unless your organization permits it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Natural-Language Policy Violations

Medium
Confidence
83% confidence
Finding
The description states the skill is a senior bid-evaluation expert '服务全国' and is entirely framed around the PRC legal system, effectively constraining responses to a China-specific legal/locale context. The file does not indicate any user choice or opt-in for language or locale, nor does it clearly scope activation to only users seeking PRC-specific advice in a way that addresses the policy concern.

Natural-Language Policy Violations

Medium
Confidence
83% confidence
Finding
This markdown file is written as mandatory operational guidance in Chinese (e.g., '铁律') and does not indicate that users may choose another language or that the Chinese-only requirement is region-specific. Under the policy rule, forcing a specific language without opt-in is a natural-language policy concern.

Natural-Language Policy Violations

Low
Confidence
88% confidence
Finding
This markdown file contains only Chinese-language content and does not indicate that the skill is limited to Chinese-speaking users or provide any user language/locale choice. Under the policy rule for natural-language violations, forcing a specific language without user opt-in can be a locale-policy issue.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The file title and all instructional content are written exclusively in Chinese, and the framework directs how responses should be structured without indicating that users may choose another language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly justified.

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
The file is entirely in Chinese and line 19 states that when a user uses incorrect terminology, the assistant must correct the terminology before answering. This imposes a language/terminology policy without any opt-in or indication that the skill is limited to a Chinese legal-compliance context, which can violate the rule against forcing a specific language or locale without user choice.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.