Back to skill

Security audit

gp-objection-reply-advisor

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed government-procurement reply drafting aid, with no executable code, but users should review legal drafts carefully and approve or remove its fixed author footer before sending.

Install only if you need Chinese government-procurement objection reply assistance. Treat outputs as legal/procedural drafts for qualified human review, verify all cited laws and project facts, keep the internal complaint-risk section out of external replies, and remove or explicitly approve the author signature before sending formal documents.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The skill hard-codes a Chinese signature/output convention at the end of generated content without indicating that language should follow the user's preference. This can override user intent, reduce transparency, and cause confusing or policy-inconsistent outputs in multilingual contexts, though it is not directly enabling code execution or data exfiltration.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The trigger phrases are fairly broad natural-language requests such as '质疑函怎么回' and '供应商质疑怎么办', which can match ordinary conversation outside a tightly scoped legal-assistance workflow. This can cause unintended activation in contexts where the user is only discussing procurement disputes generally, leading the skill to engage on sensitive legal/procedural content without clear intent or sufficient case materials.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The report explicitly notes that the skill contains a "forced-signature" instruction that appends content without user opt-in. Even though this file is only describing the issue, the underlying skill behavior is a real prompt-injection/output-manipulation risk because it can cause the agent to add unsolicited text to responses, violate platform policy, and override user intent. In this government-procurement context, forced appended language could also create legal or reputational problems if users believe the injected signature or disclaimer was intentionally part of the answer.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.