Back to skill

Security audit

Opc Demand Note Compliance

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Chinese-language compliance reference skill for reviewing demand promissory notes, with no executable code or hidden system access in the artifact.

Before installing, be aware that this skill may handle sensitive contracts, payment messages, and compliance documents. Use it as a checklist and review aid, confirm jurisdiction-specific legal points with qualified counsel, and avoid uploading confidential financial documents unless the agent environment is appropriate for that data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The activation text is broad enough to trigger on almost any request loosely related to demand notes, promissory notes, SWIFT validation, fraud, or note compliance. Over-broad routing can cause the agent to invoke this skill in contexts where specialized legal/compliance guidance is inappropriate or where another skill should handle the task, increasing the chance of misleading advice, unnecessary document handling, or policy bypass through misclassification.

Natural-Language Policy Violations

Medium
Confidence
79% confidence
Finding
The skill content appears to assume Chinese-language operation throughout without offering language negotiation or documenting a strict jurisdictional requirement. This can lead to user misunderstanding of legal/compliance advice, incorrect document interpretation, and operational mistakes when non-Chinese-speaking users or multilingual documents are involved, though the issue is primarily reliability and safety rather than direct code execution risk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.