Back to skill

Security audit

营销文案合规审查

Security checks across malware telemetry and agentic risk

Overview

The skill is a coherent jewelry-ad compliance reviewer, but it asks the agent to persist reports and update its future review word library from user-provided complaint data without clear confirmation or controls.

Install only if you are comfortable with the agent saving compliance reports in the workspace and potentially changing the skill's future word library from supplied complaint examples. Prefer confirming before any file is written or word-library entry is added, especially in shared workspaces.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The skill directs the agent to write compliance reports to workspace files and create directories, which expands behavior from in-chat analysis into persistent side effects. This increases data retention risk, may store sensitive marketing copy without clear user consent, and creates an unnecessary file-write capability for a review-only skill.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
The skill instructs the agent to modify a persistent reference file using user-provided 'historical complaint' data, allowing untrusted input to alter future behavior. This is a cross-session prompt/data poisoning risk: a malicious user can seed biased or harmful rules into the word library and influence later compliance reviews.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrases are broad everyday language such as '审一下这段文案', which can cause the skill to activate in contexts the user did not intend. Over-broad invocation raises the chance of inappropriate data processing, unnecessary file output, and accidental application of legal-review logic to unrelated text.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.