Back to skill

Security audit

标事通标书智能写作

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly coherent and disclosed, but its bundled progress monitor can poll the cloud API far too aggressively for a long-running background workflow.

Review this before installing if you will process sensitive bid, pricing, company, or personal information. The cloud upload, account retention, API-key storage, and paid word-balance behavior are disclosed, but the progress monitor should be used with a much slower interval or fixed upstream to avoid excessive API polling.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
The `progress-stream` command defaults to polling every 0.015 seconds (about 66 requests/second), which is far above the service's documented 60 req/min limit elsewhere in the file. This can easily trigger self-inflicted denial of service, rate limiting, excess backend load, and noisy failure behavior, especially if multiple jobs or users invoke it concurrently.

Vague Triggers

Medium
Confidence
80% confidence
Finding
The skill advertises very broad trigger phrases covering common bidding conversations, which can cause over-activation in ambiguous contexts and lead users to share sensitive tender or bid documents before necessity is established. In this domain, uploaded files may contain pricing, trade secrets, and personal information, so loose invocation boundaries increase the risk of unintended data exposure to the cloud service.

VirusTotal

VirusTotal engine telemetry is currently stale for this artifact.

View on VirusTotal

Static analysis

No suspicious patterns detected.