Back to skill

Security audit

Zhangxiaolong Product Way

Security checks across malware telemetry and agentic risk

Overview

This is a text-only product-advice skill with a visible but off-topic finance note, and it does not execute code, access data, or persist anything.

Install this only as a product-thinking and UX tradeoff aid. Do not treat its finance or macro update as investment, legal, regulatory, or current-events advice, and prefer more specialized sources for those topics.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The skill is presented as a product-minimalism advisor, but it injects unrelated investment and financial-analysis material into its core documentation. This creates scope confusion and can cause the agent to surface financial guidance in contexts where users expected product advice, increasing the risk of off-domain recommendations and unsafe authority bleed.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation phrases are very broad generic product questions, with no boundaries on domain, user intent, or exclusions. This can trigger the skill for ordinary product-design discussions outside its intended niche, leading to over-application of its persona and potentially irrelevant or misleading guidance.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.