Security audit
投标文件智能写作助手
Security checks across malware telemetry and agentic risk
Overview
This skill is a disclosed bid-document assistant that uploads user-selected tender files to its cloud API and stores only purpose-aligned local outputs and credentials.
Install only if you are comfortable uploading tender and bid files to the 百炼®标书 cloud service under your own API account. Keep the API key out of chat, review the service's retention/account controls, and use the duplicate-check feature only for files you are authorized to process.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
65/65 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
