Back to skill

Security audit

招标文件解读工具

Security checks across malware telemetry and agentic risk

Overview

The skill is a disclosed cloud-based bidding document assistant, with one small local metadata cache disclosure gap.

Install only if you are comfortable uploading tender and bid files to biaoshu.zhiliaobiaoxun.com under your own API key. Keep the API key out of chat, review the service's retention/account controls, and note that generated outputs plus a small local filename-to-job cache may remain on disk.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Description-Behavior Mismatch

Low
Confidence
88% confidence
Finding
The code stores tender document filenames mapped to project_id/job_id in ~/.zcm/projects.json, which is outside the declared output directory and not clearly disclosed by the skill description. While it does not store file contents or API keys there, filenames can still contain sensitive business information, procurement names, or identifiers, creating an unexpected local privacy footprint.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.