Back to skill

Security audit

Govproc Response Compliance Advisor 1.0.1

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed government-procurement checklist skill with no executable code, persistence, or hidden data movement, though users should notice its fixed Chinese report format and mandatory feedback footer.

Installers should expect Chinese-language, checklist-style outputs and a required author/feedback footer on generated reports. Avoid sharing sensitive bid prices or trade-secret materials unless the platform environment is appropriate for that information.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Context-Inappropriate Capability

Medium
Confidence
96% confidence
Finding
The skill requires every generated compliance report to append unrelated branding and an external feedback/contact channel. In a procurement-compliance context, mandatory footer insertion can leak users toward off-platform contact, create endorsement/impartiality concerns, and introduce unneeded data-sharing risk if users seek help through that channel. The explicit '必附' requirement makes this more concerning because it is enforced on all outputs rather than presented as optional metadata.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger list contains broad natural-language phrases such as '中小企业声明函怎么填' and '政采质疑投诉怎么提' that can match ordinary user questions, increasing the chance of unintended invocation. In a skill that imposes rigid workflow, legal/compliance framing, and mandatory structured output, accidental activation can override user intent, misroute conversations, or expose uploaded documents to unnecessary processing under the wrong skill.

Natural-Language Policy Violations

Medium
Confidence
82% confidence
Finding
The output contract hard-codes a Chinese structured checklist format for every reply, without user choice. While not directly enabling code execution or data exfiltration, forced language/output policy can impair usability, cause misunderstanding for non-Chinese users, and make the assistant fail user instructions about language or format in multilingual environments. Because this skill addresses legal/compliance matters, clarity and user control over language are especially important.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.