Back to skill

Security audit

决策推演工具

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed strategic decision-coaching framework with templates and a local scoring helper, and I found no hidden data access, persistence, network behavior, or destructive actions.

Install this if you want a forceful Chinese-language strategic decision review workflow. Use explicit invocation when possible, because broad phrases like strategy review or choosing a direction may activate it during normal planning conversations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger list contains very broad natural-language phrases such as '战略推演 / 选方向 / 决策推演', which can plausibly appear in ordinary discussion and cause accidental skill activation. In an agent environment, overly permissive activation expands the chance that the skill runs in unintended contexts, potentially overriding user expectations or interfering with more appropriate skills.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The installation/usage text says that speaking any trigger phrase will activate the skill, but it does not define boundaries, exclusions, or disambiguation behavior. That ambiguity can cause unintended invocation from routine strategic conversation, increasing the risk of accidental execution in contexts where the user did not mean to call this skill.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The English instructions repeat the same underspecified 'any trigger phrase' model, which broadens accidental activation for English-speaking users as well. Cross-language ambiguity increases the activation surface and makes unintended skill routing more likely in multilingual environments.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The description uses broad trigger phrases such as '战略推演' and '选方向' that can match routine user conversation, causing the skill to activate when the user did not explicitly request it. Over-broad invocation increases prompt-surface exposure and can override the expected assistant behavior in unrelated contexts, leading to confusing or unsafe instruction injection at the orchestration layer.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The skill is entirely written to operate in Chinese and does not offer language negotiation or state a justified locale restriction. In a multilingual environment, this can cause the assistant to switch languages unexpectedly, reducing user comprehension and making it harder for users to notice or correct risky guidance.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.