Back to skill

Security audit

ai-law-consultant

Security checks across malware telemetry and agentic risk

Overview

The skill is a disclosed PRC AI-law compliance reference with an optional local checklist script and no evidence of hidden access, persistence, or data exfiltration.

Install this only if you want PRC-focused AI compliance guidance. Confirm your jurisdiction and consult qualified counsel for formal legal decisions, especially outside China or for high-stakes business, administrative, or criminal exposure.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The skill hard-codes a China-only legal framework and Chinese-language interaction model without checking the user's jurisdiction, language, or whether they want PRC-specific guidance. In a legal-compliance context, this can mislead users outside China or users asking for comparative/general guidance, causing them to rely on inapplicable legal advice and miss obligations in their actual jurisdiction.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrase at line 52 appears to be overly broad for a legal-compliance skill and could cause the skill to activate on general AI-related requests that are not specifically about law or compliance. This can misroute user queries, produce irrelevant legal framing for non-legal tasks, and increase the chance of unintended disclosure of legal-style guidance where it was not requested.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.