Back to skill

Security audit

投标文件智能写作助手

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed bid-document assistant that uploads user-selected tender files to its cloud API and stores only purpose-aligned local outputs and credentials.

Install only if you are comfortable uploading tender and bid files to the 百炼®标书 cloud service under your own API account. Keep the API key out of chat, review the service's retention/account controls, and use the duplicate-check feature only for files you are authorized to process.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.