Kimi文件传输

Security checks across malware telemetry and agentic risk

Overview

This skill openly uploads user-requested local files into a Kimi chat, so it is purpose-aligned but should be used carefully with sensitive files.

Install only if you want your agent to send selected local files into Kimi. Before each upload, check the exact paths and avoid passwords, SSH keys, API tokens, private records, proprietary documents, or any file you would not intentionally share in that conversation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases and examples are broad enough to match ordinary requests about sending files, which can cause the skill to activate in contexts where the user did not explicitly consent to local file exfiltration. Because the skill is designed to upload arbitrary local files into a chat, accidental or ambiguous invocation materially increases the risk of unintended disclosure of sensitive data.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill explicitly supports uploading arbitrary local files but does not warn users that invoking it can send any locally accessible file into the Kimi conversation. In a file-transfer context, that omission is dangerous because users may not understand that sensitive files, credentials, private documents, or system data could be exposed through a simple natural-language request.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal