Back to skill

Security audit

企业招引可行性分析

Security checks across malware telemetry and agentic risk

Overview

This is a prompt-only public-source business feasibility reporting skill with disclosed limits and no hidden code or privileged behavior.

Before installing, treat this as a public-source research and report-generation skill. Verify cited facts before using its recommendations for outreach, avoid adding private contact information, and confirm any inferred expansion or relocation interest through formal channels.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill defines broad activation criteria around generic investment-attraction analysis without clear exclusion boundaries, which can cause the agent to engage in sensitive corporate targeting workflows in contexts where the user intent is vague or insufficiently scoped. In this skill, over-activation is more concerning because later instructions drive extensive data gathering, relationship mapping, and contact-path planning, increasing the chance of inappropriate or overly invasive business intelligence output.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The listed trigger phrases are common consulting and research requests that overlap with ordinary business analysis, making accidental activation likely. In this skill context, that ambiguity is riskier because activation leads to generation of expansion signals, local relationship analysis, and contact strategies for specific enterprises, which can facilitate sensitive profiling even if based on public data.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.