Back to skill

Security audit

紫苏叶·瓶颈猎手 | ShisoLeaf Alpha

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed investment-research methodology skill with no executable code, persistence, credential use, or hidden data access.

Before installing, understand that this skill may strongly frame stock research around a specific bottleneck-investing thesis; verify claims independently, consider your own financial suitability, and ask the agent to respond in your preferred language if needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The manifest description contains many broad 'Use when' triggers spanning multiple overlapping investing and supply-chain tasks, which can cause the agent to invoke this skill outside narrowly intended contexts. Over-broad activation increases the chance the skill is selected for general financial-analysis requests where its strong methodology and persuasive claims may steer outputs inappropriately or without sufficient suitability checks.

Natural-Language Policy Violations

Medium
Confidence
76% confidence
Finding
The skill body is written entirely in Chinese and does not instruct the agent to match the user's language or offer alternatives, which can lead to inaccessible or confusing interactions for non-Chinese-speaking users. While this is not a direct security exploit, it can degrade transparency and informed user consent, especially in a financial-analysis context where users need to clearly understand assumptions and risks.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.