Security audit
政采质疑答复“判例法”智库
Security checks across malware telemetry and agentic risk
Overview
This is a narrowly scoped government-procurement case-matching and reply-drafting skill with disclosed knowledge-base use and no hidden install code.
Install this only for PRC government-procurement objection response work where querying the named IMA knowledge bases is expected. Treat generated legal conclusions and draft reply letters as review material for counsel or procurement staff, and do not allow any suggested pattern-library updates to modify installed skill files without explicit approval.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
