Back to skill

Security audit

供应商与企业全景尽调Supplier Panorama Dd 1.0.0

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Chinese-language supplier and company due-diligence workflow using public web and knowledge-base research, with no hidden install, persistence, or destructive behavior found.

Install this if you want Chinese-language public-source supplier or company due diligence. Treat its outputs as decision support, verify major legal or procurement conclusions manually, and be aware that its default workflow may search public records for related parties as well as the target company.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are broad natural-language business requests such as supplier due diligence and partner background checks, which can overlap with ordinary conversation and cause the skill to activate when the user did not explicitly ask for it. In a tool-equipped skill, unintended activation can steer the assistant into a rigid workflow, cause unnecessary data gathering, and override user intent in adjacent procurement, partnership, or investment discussions.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The skill is written to operate in Chinese by default, with Chinese-only description, triggers, and examples, but does not declare a locale restriction or ask the user for language preference. This can create unintended behavior where users in other languages trigger the skill but receive inaccessible output or misinterpreted inputs, reducing reliability and potentially causing incorrect compliance or due-diligence conclusions.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.