Back to skill

Security audit

澍脉投放驾驶舱

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed, read-only connector for querying Shumai advertising diagnostics, with no evidence of hidden persistence, mutation, or unrelated data handling.

Install this only if you intend Codex to query Shumai using SHUMAI_API_KEY for advertising diagnostics. The skill is read-only, but it can retrieve sensitive account metrics and recommendations, so keep the API key scoped appropriately and be aware that broad ad-performance questions may trigger this integration.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
79% confidence
Finding
The trigger description is broad enough to activate on common advertising-performance questions, which can cause the agent to route more user requests than intended to an external service. That increases the chance of unnecessary data access or disclosure of account-specific ad metrics when the user did not explicitly request this integration.

Natural-Language Policy Violations

Medium
Confidence
72% confidence
Finding
Forcing all responses into Chinese without checking the user's language preference can override user intent and impair transparency about what the tool returned. In multilingual environments, this may lead to misunderstanding of sensitive account diagnostics or recommendations, indirectly increasing operational risk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.