ZDAT Crawl Skill

Security checks across malware telemetry and agentic risk

Overview

The skill is a disclosed web-monitoring and alerting helper, with no hidden installer or implemented exfiltration behavior found.

Install only if you want scheduled intelligence monitoring. Before enabling cron jobs or enterprise WeChat alerts, define the keyword lists, crawl sources, output files, alert recipients, and thresholds, and review whether the collected public information is appropriate for your organization to store and redistribute.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrases are broad business terms like '舆情', '情报采集', and '竞品监控', which can match many ordinary user requests and cause the skill to activate unexpectedly. In a skill that performs automated crawling and monitoring, ambiguous activation increases the chance of unintentional external actions, data collection, or workflow execution without clear user intent.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly describes automated web data collection, writing competitor information to Excel, and pushing alerts to enterprise messaging, but it provides no user-facing notice, consent step, or guardrails around those external effects. That is dangerous because the skill could collect, store, and disseminate sensitive or regulated information, or trigger organization-facing notifications, without the operator understanding the consequences.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal