Back to skill

Security audit

破晓

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Chinese stock-market report generator with purpose-aligned web browsing and file export guidance, but users should review its broad auto-load triggers and fixed save-path examples.

Install this if you want a Chinese A-share report workflow that browses public finance sites for current data. Consider narrowing or disabling global auto-load triggers, confirm any file save location before output, and only run PDF export when you explicitly need it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger keyword list includes broad, common terms such as '早报', '午评', '收盘', and '复盘', which can match many ordinary finance-related conversations and auto-load the skill globally. In a global auto-load configuration, this increases the chance of unintended activation, causing the agent to follow this skill's prescriptive browsing workflow when the user did not explicitly request it.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The generic trigger scenarios are underspecified and say that terms like '破晓' and '股市资讯' should '自动判断时间', but they do not define clear boundaries, exclusions, or confirmation behavior. Combined with auto-load and global scope, this ambiguity can cause the skill to activate in loosely related contexts and initiate external browsing or data collection without clear user intent.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The skill content is entirely in Chinese and prescribes Chinese-language output without indicating any mechanism to honor the user's preferred language. This can cause misunderstandings, reduce accessibility, and make downstream review harder for non-Chinese-speaking users or operators, though it is not a direct security exploit. In this financial-reporting context, language rigidity can also increase operational risk because users may misinterpret market data or warnings.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill instructs saving generated files to a fixed absolute local path on the user's desktop without requiring explicit consent or confirming that local file creation is expected. This can cause unintended writes, overwrite existing files with predictable names, and leak sensitive report content into a visible local location, especially in automated agent environments.

Missing User Warnings

Low
Confidence
90% confidence
Finding
The PDF export guidance directs the agent to open HTML in a browser tool or invoke conversion utilities, which can create or transform additional files without clearly informing the user. In agentic contexts, this expands side effects beyond simple text generation and may expose local content to extra tooling or leave behind derivative artifacts the user did not expect.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.