Back to skill

Security audit

投标文件智能生成

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed bid-document assistant that uploads user-selected tender files to one stated service and stores only local configuration and outputs needed for that workflow.

Before installing, confirm you are comfortable uploading tender and bid documents to biaoshu.zhiliaobiaoxun.com under your API-key account. Do not paste the API key into chat; keep it in the local config file, and review or delete generated reports and the small local project cache if the documents are sensitive.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Lp3

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding
Without declared permissions the skill's intent is opaque and cannot be validated.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The description says the skill should be used when users ask phrases like '帮我写投标书' or '检查标书有没有问题', alongside a very long scene list. Some of these phrases are broad natural requests that could overlap with general writing or document-review conversations unless the trigger is tightly constrained to tender/bid documents.

Natural-Language Policy Violations

Low
Confidence
93% confidence
Finding
The entire skill documentation is written only in Chinese and provides operational instructions exclusively in that language. Under the policy, forcing a specific language without user opt-in can be a natural-language locale violation unless the regional constraint is explicitly documented and justified.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.