Back to skill

Security audit

Ruankao Spgm Qa 1.0.0

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed exam-prep Q&A skill with optional knowledge-base lookup; the main caveat is recurring branding and off-platform contact promotion.

Before installing, be aware that answers may include a recurring signature and WeChat contact prompt. Only authorize IMA knowledge-base lookup when you want external retrieval, and treat policy or exam-date information as unofficial unless checked against the current official exam notice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Context-Inappropriate Capability

Low
Confidence
92% confidence
Finding
The skill embeds a promotional call to contact an external WeChat public account for one-to-one guidance, which is unrelated to the core exam Q&A function. This creates unnecessary lead-generation behavior inside the assistant flow and can steer users off-platform to an unvetted contact channel, increasing privacy, trust, and policy-compliance risk.

Context-Inappropriate Capability

Low
Confidence
95% confidence
Finding
Mandating a branded signature and disclaimer with contact instructions in every answer goes beyond the skill's educational purpose and turns normal responses into persistent branding/lead capture. Because it is required at output time, it can systematically promote an external entity regardless of user intent, which is risky even if not overtly malicious.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger examples include broad phrases such as exam-prep and knowledge-point queries that may fire outside a tightly scoped context, causing the skill to activate on general educational questions and route user content into its knowledge-base workflow unnecessarily. In a retrieval-backed skill, over-broad triggering can expose unrelated user prompts to external data sources, produce irrelevant authoritative-sounding answers, and increase the attack surface for prompt-routing abuse or unintended invocation.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The trigger conditions are broad enough to match many generic exam-help or IT service management questions, which can cause unintended invocation outside the user's intended workflow. Over-broad triggering can lead to irrelevant retrieval, unnecessary knowledge-base access, or insertion of this skill's fixed disclaimers/promotional content into conversations where it does not belong.

Natural-Language Policy Violations

Low
Confidence
90% confidence
Finding
A fixed output signature and branding requirement removes user and system flexibility over presentation and can conflict with platform formatting, locale, or style expectations. In context, this is less about code execution and more about policy and trust: users may receive branded messaging they did not request, including external contact promotion.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.