Back to skill

Security audit

Anti Scam Expert

Security checks across malware telemetry and agentic risk

Overview

This is a text-only Chinese anti-scam analysis skill with reference materials and no evidence of hidden code, data access, or unsafe automation.

Install this if you want Chinese-language scam-risk analysis and examples. Use it as a practical warning tool, and confirm serious financial, legal, law-enforcement, or account issues through official channels before acting.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
85% confidence
Finding
The trigger description is broad enough to activate on many ordinary trustworthiness or risk-evaluation questions, not just clear scam-analysis cases. Over-broad routing can cause the system to overuse this skill, bias responses toward fraud framing, and misclassify benign business, investment, or product questions as scams without sufficient context.

Natural-Language Policy Violations

Medium
Confidence
78% confidence
Finding
The skill is written entirely in Chinese and its output format assumes Chinese-language operation, without stating that it is restricted to Chinese-speaking users or providing language fallback behavior. In a multilingual agent, this can lead to incorrect routing, inaccessible outputs, or degraded user understanding, which is a policy and usability weakness even if not a direct exploit primitive.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.