Back to skill

Security audit

注塑模具专家 · MoldYang

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed injection-molding reference skill with no executable behavior, persistence, credential access, or hidden data flow.

Before installing, be aware that generated deliverable files may include MoldYang attribution and contact details at the top. If that conflicts with your organization’s document branding, customer-facing templates, or confidentiality rules, disable or edit that output rule before using the skill for external reports.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Context-Inappropriate Capability

Low
Confidence
95% confidence
Finding
The skill mandates insertion of author attribution and direct contact details into any generated external document, regardless of user intent or deployment context. This is not necessary for performing molding-engineering assistance and creates an unnecessary instruction that can cause unauthorized disclosure of personal contact information, branding injection into outputs, and policy conflicts when the agent is used in enterprise or customer-facing workflows.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.