Back to skill

Security audit

国企采购评审专家

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Chinese SOE procurement-compliance guidance skill with no executable code, persistence, credential use, or hidden data handling.

Install only if you want Chinese-language SOE procurement compliance guidance. Treat its legal and procurement answers as decision support, verify against current laws, internal procurement rules, and counsel, and be aware that it may use the disclosed external ima knowledge-base links when available.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The file hard-codes Chinese-only response behavior and source-labeling conventions without any user language choice or fallback. This can exclude users who operate in other languages, increase misunderstanding of compliance guidance, and create usability and accessibility risk in a high-stakes procurement context.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.