Back to skill

Security audit

政企行政助手Gov Entity Admin

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Chinese administrative drafting skill with no executable code, but users should verify dates and placeholders because some examples fill in details not present in the prompt.

Install only if you want a Chinese government or enterprise administrative drafting helper. Review generated official-looking details carefully, especially dates, locations, deadlines, document numbers, and attendees, and replace unsupported fields with 待补/待定 before use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The skill explicitly says missing fields must be marked as '待补' and that data must not be fabricated, yet the examples introduce concrete dates, locations, and deadlines not present in the user inputs. This can train or bias the agent to invent official-looking administrative facts, which is risky in government or enterprise workflows because users may rely on generated details as authoritative.

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
There is a direct contradiction between the boundary rule '不臆造文号、法条、数据' and the examples, which supply specific dates and scheduling details not provided by the user. In an administrative drafting skill, this inconsistency can cause fabrication of records, deadlines, or meeting metadata, undermining procedural integrity and potentially creating compliance or audit issues.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The README advertises activation via broad natural-language examples such as drafting meeting minutes or sending reminders, which are common everyday requests and may cause the skill to trigger outside the user's explicit intent. In an administrative skill, accidental activation can expose sensitive internal drafting context, steer responses into a constrained workflow unexpectedly, or create confusion about whether the assistant is acting as a generic helper versus a specialized government/enterprise admin tool.

VirusTotal

57/57 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.