Back to skill

Security audit

小晓投标文件生成

Security checks across malware telemetry and agentic risk

Overview

This skill mostly matches its stated bid-document cloud workflow, but it needs Review because it persists local project metadata outside the declared write scope and its progress monitor can create excessive API traffic.

Before installing, confirm you are comfortable uploading tender and bid files to the 百炼®标书 cloud service under your API-key account, where results may remain available for about 7 days. Treat the API key as a full account credential, and prefer a slower explicit progress polling interval until the default is fixed. Also be aware that tender filenames and job/project IDs may be cached locally under ~/.zcm unless configured otherwise.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Context-Inappropriate Capability

Low
Confidence
86% confidence
Finding
The progress-stream command polls job status at a default interval of 15ms, which can generate extremely high request volume against the remote API. This creates a client-enabled denial-of-service/rate-limit abuse vector and is disproportionate to legitimate progress monitoring needs, especially since the same file documents a 60 req/min limit.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.