Back to skill

Security audit

招商项目评估报告

Security checks across malware telemetry and agentic risk

Overview

This is a markdown-only investment project assessment skill with disclosed research use and no hidden execution behavior.

Before installing, expect the agent to perform structured public/business research about named projects or companies and produce decision-support recommendations. Verify source data independently, avoid treating the report as legal or financial advice, and do not provide confidential project materials unless you are comfortable using them in the agent workflow.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
82% confidence
Finding
The activation condition is broad and does not define exclusion boundaries, so the orchestrator may invoke this skill for loosely related business-analysis or due-diligence requests. That can cause over-collection of data, inappropriate tool use, or overly authoritative investment-style recommendations outside the intended scope, especially because the skill calls multiple external analysis tools.

Vague Triggers

Medium
Confidence
85% confidence
Finding
Several triggers are semantically broad, such as evaluating investment feasibility or forming a report, and could match ordinary advisory conversations that are not true skill invocations. In this context, accidental triggering is more dangerous because the skill is framed as a formal decision-support process and may produce structured conclusions or initiate tool-assisted diligence on insufficiently scoped requests.

VirusTotal

53/53 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.