Back to skill

Security audit

Contract And Tender Document Consistency Review Assistant 1.0.0

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent contract-and-bidding consistency reviewer, with disclosed sensitive document handling but no hidden execution, persistence, or exfiltration behavior found.

Installers should treat this as a sensitive legal/compliance document-review skill: share only the tender, bid, award, and contract files needed for the task, verify any cited legal authority against official sources, and do not grant local document write access unless they intentionally want editable output or supervised revisions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrase “签约前核对” is broad enough to match many ordinary pre-signing review requests that may not actually involve tender/bid consistency analysis. This can cause unintended invocation of a specialized compliance skill, leading to unnecessary exposure of contract documents and confusing or overreaching analysis in workflows handling sensitive procurement materials.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The single-term trigger “阴阳合同” is ambiguous and can appear in news, discussion, education, or legal consultation contexts unrelated to this skill’s intended document-comparison workflow. This raises the risk of accidental activation and inappropriate routing of sensitive user content into a compliance-review process that may query linked knowledge bases or attached files.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger “黑白合同” has the same ambiguity problem as other single-term labels: it may be used in abstract discussion or non-procurement legal contexts, yet it would still invoke this skill. In a system that can access local documents and external knowledge bases, unintended invocation increases the chance of privacy leakage, mis-scoped analysis, and user confusion.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The manifest advertises optional capabilities to read local Office/PDF files and perform real-time writing to local .docx/.wps documents, but it does not state any safeguard such as explicit user consent, read-only default behavior, backup creation, or change preview. In a legal-contract review context, silent or poorly signaled document modification is particularly risky because it can alter evidence, introduce drafting errors, overwrite authoritative versions, or create compliance and audit disputes.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.