Back to skill

Security audit

易企秀H5制作

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a legitimate 易企秀 H5 generator, but it uses account tokens and can upload local files to third-party services with broader-than-ideal activation and limited safety warnings.

Review before installing. Use it only when you explicitly want 易企秀 H5 generation or editing, avoid passing tokens directly on the command line, treat the saved token as sensitive, and only upload files you are comfortable sending to Eqxiu/COS services.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger phrases are broad and overlap with ordinary creative requests such as making posters or invitations, which can cause the skill to activate in situations where the user did not intend to use this external H5 generator. Overbroad activation increases the chance of unnecessary network calls, token use, or external content generation without clear user intent.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The read-when rules are ambiguous and loosely scoped, so the skill may be loaded for common design/editing requests that do not require this integration. In context, this matters because the skill can handle tokens, uploads, and remote content generation, making accidental invocation more sensitive than a purely local or read-only skill.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The documentation instructs users to log in and store an access token in a local config file and to pass it via command line, but it does not warn that these credentials are sensitive or discuss safe handling. Tokens stored in plaintext or exposed through CLI arguments can be leaked via logs, shell history, screenshots, process listings, or unintended file access, enabling unauthorized access to the user's account and generated content.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill supports uploading local files to remote COS storage and registering them with a remote material service, but it provides no clear user warning that local files will be transmitted off-device. Without explicit notice and confirmation, users may unintentionally expose sensitive images, documents, or metadata to third-party services.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.