Back to skill

Security audit

命题工坊

Security checks across malware telemetry and agentic risk

Overview

This skill is a prompt-only contest-problem writing assistant with no file, network, credential, persistence, or command authority.

Installers should expect this skill to influence responses for Chinese OI/CSP/NOI-style problem generation. Consider narrowing triggers if you do not want it to activate on general programming exercises or algorithm-help requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger list includes very broad generic phrases such as '编程题', which can match many unrelated user requests for programming exercises rather than this narrowly scoped OI/NOI contest-authoring skill. Overbroad activation can cause the wrong skill to engage, leading to prompt hijacking of benign workflows, reduced reliability, and unintended application of this skill’s strong stylistic constraints to unrelated tasks.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The activation section says the skill should trigger for '任何算法竞赛题目需求', which is ambiguous and effectively claims a very large problem space. This increases the chance of unintended invocation on broad algorithm-help requests, where the skill may override more appropriate tools or instructions and steer outputs into contest-problem generation unnecessarily.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.