Back to skill

Security audit

知识付费出海 - 赛道评估器

Security checks across malware telemetry and agentic risk

Overview

This is a markdown-only Chinese business-evaluation skill with no hidden execution, credential access, persistence, or destructive behavior.

Install this if you want a Chinese-language framework for assessing knowledge-product export niches. Expect it to guide public market research and produce opinionated business recommendations; independently verify any benchmark numbers or platform data before making commercial decisions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The skill is described as being triggered by a very natural phrase such as '帮我评估一下XX赛道能不能出海', which overlaps with ordinary conversation and can cause accidental invocation. This can unexpectedly route user queries into this skill’s rigid evaluation flow, producing unintended behavior or confusing outputs even when the user did not explicitly intend to use the skill.

Natural-Language Policy Violations

Medium
Confidence
77% confidence
Finding
The skill content and prescribed interaction are entirely in Chinese without offering a language-selection mechanism or clarifying locale expectations. This can lead to misinterpretation, inaccessible outputs, or degraded user safety/usability when invoked by users operating in other languages or regions.

VirusTotal

57/57 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.