Back to skill

Security audit

contract-management

Security checks across malware telemetry and agentic risk

Overview

This contract-management skill is coherent, but needs Review because it can save or publish sensitive legal documents without clear opt-in and privacy guidance.

Review before installing in environments that handle confidential contracts. Use it only with documents you are allowed to process, keep Notion disconnected or require explicit local-only handling unless third-party publication is approved, and confirm the governing law before relying on legal analysis or generated contract language.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (13)

Vague Triggers

Medium
Confidence
85% confidence
Finding
The README tells users to trigger the skill through natural conversation, which can cause overly broad routing and accidental activation from ordinary chat. In a legal/contract workflow, unintended invocation may expose sensitive contract context to the wrong skill path or cause the model to process confidential documents when the user did not clearly intend that action.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The README explicitly describes uploading contracts, NDAs, and related legal documents but provides no privacy, confidentiality, or sensitive-data handling warning. Because these materials commonly contain trade secrets, personal data, and commercially sensitive terms, users may disclose highly confidential information without understanding the risks or required safeguards.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases include very broad everyday requests such as '帮我看下这份合同' and '帮我查个法条', which can cause the skill to activate for ambiguous or loosely related user inputs. In an agent setting, overbroad activation increases the chance of unintended routing into legal-review workflows, potentially causing inappropriate data handling or misleading legal-style output without the user's clear intent.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The routing logic permits matches based on broad 'scene' descriptions rather than strict, user-explicit intents, which can misclassify requests and invoke the wrong legal subskill. In a contract-management context, incorrect routing can lead to incomplete review, wrong assumptions about the task, or collection/processing of sensitive contract data under the wrong workflow.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill states that it may generate and write files, but it does not require explicit user notice or confirmation before modifying or creating artifacts. In a legal-document workflow, silent file creation or overwrite can alter sensitive documents, create misleading deliverables, or store user data in ways the user did not intend.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The skill hardcodes Chinese legal requirements as the governing standard without confirming the relevant jurisdiction. For legal analysis and drafting, applying the wrong legal regime can produce materially incorrect advice or documents, which is especially risky when users may upload cross-border, foreign-law, or unspecified-jurisdiction contracts.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The acceptance criteria default to compliance with Chinese law, again without an applicability check, which can systematically validate outputs against the wrong legal standard. This is dangerous because it can create false confidence that a contract is compliant when the actual governing law is different.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly offers publishing contract comparison reports to Notion but does not warn that uploaded contracts may contain confidential, personal, or commercially sensitive information that would be transmitted to a third-party service. In a contract-management context, this materially increases data leakage and unauthorized sharing risk because users may assume publication is a harmless formatting step rather than an external disclosure.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
Publishing draft contracts to Notion can expose highly sensitive commercial, legal, and personal data to a third-party service without any explicit privacy warning, consent check, or data-minimization step. In the context of contract drafting, the documents often contain counterparties, pricing, tax, dispute, and signature details, so silent upload increases confidentiality and compliance risk.

Missing User Warnings

Low
Confidence
88% confidence
Finding
Writing the generated contract to a local .docx file creates a persistent copy of sensitive legal content on disk without warning the user about storage location, access controls, or cleanup. While local output is often expected behavior, this skill handles confidential contracts, so failure to surface retention and endpoint-security implications can lead to unintended disclosure on shared or unmanaged devices.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The skill hard-codes Chinese law as the governing review basis and mandates Chinese-language output without first confirming the user's jurisdiction, applicable law, or preferred language. In a legal-review workflow, this can cause materially incorrect advice, omit relevant local law, or make output unusable for the user, especially in cross-border or non-Chinese matters.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs publishing contract reports and reminder lists to Notion but does not warn that these records may contain sensitive commercial terms, counterparties, dates, owners, and lifecycle status. Sending such data to a third-party workspace without explicit consent, minimization, access-control guidance, or redaction steps can cause unauthorized disclosure of confidential legal and business information.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill invites users to upload contract files and Excel ledgers for automated extraction without any notice that these materials often contain highly sensitive legal, financial, and personal data. In a contract-management context, this omission is more dangerous because users are likely to submit entire agreements, counterpart information, milestone schedules, and responsible-person details, increasing the risk of over-collection and unintended exposure.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.