Back to skill

Security audit

Huang Renxun Ai Strategy

Security checks across malware telemetry and agentic risk

Overview

This appears to be a text-only strategy-analysis skill with some scope drift into broader market and investment-style templates, but no evidence of hidden execution, data access, persistence, or exfiltration.

Install only if you want a Jensen Huang/NVIDIA strategy assistant that may also produce broader AI-market or investment-style analysis. Treat any financial output as research support, not investment advice, and keep prompts tied to the intended NVIDIA strategy scope.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The skill’s declared scope is a Jensen Huang/NVIDIA strategy advisor, but the appendix introduces broader market-analysis and quasi-investment report templates that materially extend behavior beyond that scope. This can cause unintended activation or misuse for generic financial analysis, increasing the chance users receive more actionable market guidance than the safety framing suggests.

Intent-Code Divergence

Medium
Confidence
88% confidence
Finding
The trigger section claims the skill should activate only for Jensen Huang/NVIDIA-direct topics, yet later content includes reusable templates for broad AI industry and market report generation. This mismatch can undermine routing boundaries and make the skill respond in contexts it says it should not, weakening user expectations and policy controls.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.