Back to skill

Security audit

慧中标标书写作工具

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed bid-document assistant that uploads user-selected tender files to a named external service and stores an App Key locally for that service.

Install only if you are comfortable uploading tender and bid files, which may contain business or personal information, to biaoshu.zhiliaobiaoxun.com under your App Key account. Keep the App Key out of chat, verify any ZCM_BASE override before use, and confirm billing/points before generating full bid documents.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
82% confidence
Finding
The skill description is very broad and can match a wide range of generic requests about bid writing, review, or document handling. Overbroad activation increases the chance the skill is invoked on loosely related prompts, causing unintended file access, document upload to the external service, or credential-guided workflows without the user clearly intending to use this integration.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.