Back to skill

Security audit

项目选址分析报告

Security checks across malware telemetry and agentic risk

Overview

This is a Chinese project-landing risk report skill with no executable code, hidden persistence, destructive behavior, or credential handling.

Install if you need Chinese-language project landing risk reports. Users should provide verified project and enterprise data, review any enterprise credit or policy findings manually, and avoid treating the report as a substitute for legal, financial, environmental, or safety due diligence.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
82% confidence
Finding
Several trigger phrases, such as analyzing construction, operations, market, or policy risk, are broad enough to match generic project-analysis requests and may cause the skill to activate outside its intended招商/落地风控 context. Over-broad activation can route users into a rigid risk-assessment workflow unexpectedly, increasing the chance of irrelevant tool use, unnecessary data collection, or misleading risk conclusions in unrelated scenarios.

Natural-Language Policy Violations

Medium
Confidence
71% confidence
Finding
The skill is authored as Chinese-only without a documented locale restriction or language negotiation path, which can cause users to receive or submit critical risk-analysis content in a language they do not fully understand. In a decision-support skill dealing with compliance, funding, safety, and policy risks, misunderstandings can degrade accuracy and lead to poor decisions, though this is more a quality/safety issue than a direct security exploit.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.