Back to skill

Security audit

政采投诉策略“胜诉率”预判

Security checks across malware telemetry and agentic risk

Overview

This skill is a Chinese government-procurement complaint analysis workflow with disclosed knowledge-base use and no hidden execution, persistence, or data exfiltration.

Before installing, confirm that users need Chinese mainland government-procurement complaint analysis and that the named knowledge bases are available. Treat its percentage outputs as statistical aids only, and verify any legal conclusions with current law or a qualified professional.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The skill content is entirely written in Chinese and explicitly targets a Chinese government procurement workflow, with no indication of language negotiation or fallback. This can cause misrouting, misunderstanding, or exclusion for users who do not read Chinese, especially if the hosting agent invokes the skill automatically based on trigger phrases rather than explicit user locale selection.

VirusTotal

42/42 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.