Back to skill

Security audit

投标文件自动生成

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed bid-document assistant that uses one stated cloud API, user-provided files, and a locally stored API key for its advertised workflow.

Before installing, understand that tender and bid files may contain business, pricing, and personal data and will be uploaded to the named 百炼®标书 cloud service under your API-key account. Keep the API key out of chat, confirm you have rights to process all uploaded documents, and review the service's retention/account controls for your organization.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding
Without declared permissions the skill's intent is opaque and cannot be validated.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding
This is a mismatch because the description presents the skill as an end-user tool for interpreting tenders, generating bid documents, reviewing bids, and duplicate checking, but the code implements a broader API client/utility suite. In addition to the described core bidding functions, it also exposes account management, credential persistence, knowledge-base access, package extraction, generic job control, progress streaming, artifact download, and report rendering from existing JSON/job outputs. Those are real capabilities not reflected in the declared description. The core described functions are present, but the description does not accurately represent the full behavior of the code.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.