Back to skill

Security audit

AI智写标书制作工具

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed bid-document automation tool that uploads user-selected tender files to a named cloud service and uses an account App Key for billing.

Install only if you are comfortable sending tender and bid files to biaoshu.zhiliaobiaoxun.com under your App Key account. Treat the App Key like a password because it can spend account points and access account data; keep it in the local config file, avoid pasting it into chat, and verify any ZCM_BASE override points to the intended service.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Tp4

High
Category
MCP Tool Poisoning
Confidence
86% confidence
Finding
The skill description emphasizes batch bid-document generation, but the content also exposes credential management, account/balance inspection, job control, result retrieval, and report rendering behaviors that are not clearly reflected in the top-level description. This mismatch can mislead users and reviewers about the real operational scope, especially because the skill uploads sensitive tender/bid files to a remote service and handles account-bound credentials and billing.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.