Back to skill

Security audit

gov-procurement-doc-assistant

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent tender-document analysis assistant with disclosed document reading, legal-reference lookup, optional spreadsheet output, and clear boundaries against bid writing, collusion, or guaranteed-winning advice.

Use this skill for analyzing uploaded procurement or tender documents, not for standalone bid-winning strategy. Verify legal citations and price-score calculations before relying on them, and treat its recommendation summary as decision support rather than legal, commercial, or bidding advice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrase "投标建议" is broad enough to catch general bidding-advice requests, not just tender-document interpretation tied to uploaded procurement materials. In this skill’s context, that scope creep can cause the agent to provide strategic bidding guidance outside its declared boundary, increasing the risk of unintended procurement advice or behavior adjacent to disallowed bid-winning guidance.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.