Back to skill

Security audit

镖行AI投标文件生成助手

Security checks across malware telemetry and agentic risk

Overview

This skill is a cloud-backed bid document assistant that clearly discloses uploading user-provided files, using an App Key, consuming account points, and retaining results server-side.

Install only if you are comfortable sending tender and bid documents to biaoshu.zhiliaobiaoxun.com under your App Key account. Treat the App Key like a password, prefer the documented ~/.zcm/config.json setup instead of pasting it into chat, leave ZCM_BASE unset unless you intentionally use another endpoint, and confirm uploads or point-consuming generation steps before running them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding
The skill description emphasizes document polishing and compliance review, but the actual behavior includes credential management, remote API submission, file upload, account balance checks, task control, and server-side retention of uploaded files. This mismatch can mislead users about data flows, billing, and account-scoped actions, reducing informed consent and increasing the chance that sensitive bid documents are sent off-device unexpectedly.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.