Back to skill

Security audit

项目落地风险评估报告

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent project risk-assessment template, with only a minor chance of activating for overly broad business-risk questions.

Install this if you want structured招商 or industrial project landing-risk reports. If your agent has many business-analysis skills, consider narrowing the triggers so ordinary market, policy, or project-management questions do not automatically use this more formal risk-review workflow.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill’s trigger scope is broad enough that ordinary requests about project analysis or risk discussion could activate it unintentionally. This can cause the agent to enter a highly prescriptive workflow, invoke external tools, and generate authoritative-looking risk assessments even when the user did not explicitly request this specialized skill.

Vague Triggers

Medium
Confidence
95% confidence
Finding
Several listed trigger examples are ambiguous and overlap with normal business conversation, such as generic requests to analyze construction, operation, market, or policy risks. In an agentic environment, such ambiguity increases the chance of accidental invocation, unnecessary tool use, and delivery of a formal risk judgment in contexts where a lighter or different workflow was intended.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.