Back to skill

Security audit

GP Challenge & Complaint Advisor

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Chinese-language government-procurement complaint assistant with no executable code, persistence, credential use, or hidden data access.

Install only if you want Chinese-language assistance with government procurement challenge or complaint workflows. Treat outputs as drafting and research support, verify cited cases and deadlines yourself, and consult a qualified lawyer for legal advice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger list includes very broad phrases such as “质疑” and other common conversational terms that can plausibly appear in ordinary discussion, increasing the chance the skill is invoked without clear user intent. In a legal-advisory workflow, accidental activation can expose user-provided facts or drafts to an unintended tool path and produce legal-style guidance in contexts where the user did not mean to request it.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger list contains broad, conversational phrases such as asking whether a complaint is useful or what to do after a rejection, which can overlap with normal discussion and unintentionally invoke the skill. In a procurement-complaint workflow, accidental activation can expose users to irrelevant legal-style guidance, misroute conversations, or cause the agent to treat casual text as a regulated complaint task.

Natural-Language Policy Violations

Medium
Confidence
81% confidence
Finding
The skill is written to operate exclusively in Chinese and does not provide a language negotiation or fallback path. This can cause users who interact in other languages to misunderstand legal/procedural guidance, submit incorrect complaint content, or miss important caveats and deadlines.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.