Back to skill

Security audit

政采评审专家“判例法”指引

Security checks across malware telemetry and agentic risk

Overview

This is a Chinese government-procurement guidance skill with no executable code, persistence, or hidden data handling, and its Chinese terminology is coherent with its legal domain.

Install this only if you need Chinese government-procurement review guidance. Treat its outputs as advisory, verify cited legal sources and case anchors, and ensure the named knowledge bases are mounted and current before relying on risk ratings or clarification suggestions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The README’s instructions and operational guidance are entirely in Chinese, and there is no indication that users may choose another language or that Chinese-only operation is an explicit opt-in. Under the policy, forcing a specific language without user choice is a natural-language policy concern unless clearly justified as region-specific.

Natural-Language Policy Violations

Low
Confidence
88% confidence
Finding
The instruction says outputs must uniformly use specific Chinese terms and not use alternative wording. This is a natural-language locale policy constraint, and the file does not indicate user opt-in or a language-choice mechanism.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The entire skill document is written as mandatory Chinese-language operational guidance, with no indication that users may choose another language or locale. Under the policy, forcing a specific language without opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
This markdown file contains user-facing instructional content exclusively in Chinese, and nowhere indicates that the skill is region-specific or that users may opt into another language. Under the policy rule for natural-language violations, forcing a specific language without opt-in is reportable.

VirusTotal

57/57 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.