Security audit
标书自动撰写工具
Security checks across malware telemetry and agentic risk
Overview
The skill is a disclosed bid-document assistant that uploads user-selected tender and bid files to one stated cloud service for analysis, generation, review, and similarity checks.
Install only if you are comfortable sending tender and bid documents, which may contain commercial or personal information, to the 百炼®标书 cloud service. Keep the API key in the local config file rather than chat, use only files you are authorized to process, and be aware that generated results and task history may remain available in the provider account for a limited time.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
