Back to skill

Security audit

enterprise-ai-advisor

Security checks across malware telemetry and agentic risk

Overview

This skill is a Chinese-language business AI consulting questionnaire that stays within its stated purpose and does not install code, run commands, persist data, or access local resources.

Install this if you want Chinese-language guidance for assessing business AI opportunities. Be mindful that it asks for business details and budget to estimate ROI, and it may suggest follow-up paid services, but it does not contain code or request access to your files, accounts, or credentials.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The activation text uses very broad trigger phrases like enterprise AI diagnosis, planning, consulting, and transformation roadmap, which can match many ordinary business conversations and cause the skill to activate outside a narrowly intended context. Over-broad invocation increases the chance of unsolicited guidance, unintended collection of business details, and routing users into a specialized workflow when they did not explicitly request it.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The skill content is entirely written to operate in Chinese and does not offer a user language choice or document a justified locale restriction. This can create user confusion, reduce transparency and consent during data collection, and increase the risk of misunderstandings in business recommendations if the user's preferred language differs.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.