Back to skill

Security audit

投标文件智能制作

Security checks across malware telemetry and agentic risk

Overview

This skill mostly matches its bid-document purpose, but it should be reviewed because its background progress checker can call the vendor service far too frequently while handling sensitive bid files.

Review this before installing if you will process confidential bids, pricing, personal data, or client documents. Use it only when you are allowed to upload those files to 百炼®标书, keep the API key in the local config file only, and avoid the default progress-stream polling interval unless it is raised to a sane value such as several seconds.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Context-Inappropriate Capability

Medium
Confidence
86% confidence
Finding
The progress-stream command defaults to polling the remote API every 15ms, which is far more aggressive than normal status monitoring and can generate thousands of requests per minute. Even though it targets the vendor API rather than the local system, this creates a built-in high-frequency request capability that can overwhelm the backend, trigger rate limits, or be repurposed for abusive traffic inconsistent with the skill’s document-analysis purpose.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The invocation description contains very broad, natural-language triggers covering many common procurement-related phrases, which can cause the skill to activate in loosely related conversations. Over-broad activation increases the chance of unnecessary handling of sensitive tender/bid files and cloud upload to the external service before the user clearly intended to invoke this specific workflow.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.