Back to skill

Security audit

胡田-OPC导师-专家委员会

Security checks across malware telemetry and agentic risk

Overview

This is a markdown-only Chinese decision-support skill with broad triggers and some aggressive marketing advice, but no hidden execution, data access, persistence, or exfiltration.

Install this if you want Chinese-language expert-committee style analysis. Verify any legal, policy, financial, or market claims independently before acting, and be cautious with the viral-marketing guidance because controversy-based tactics can create compliance and reputational risk.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (17)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger list is very broad and includes generic words such as '专家', '决策支持', and '多视角', which are common in ordinary user requests. This can cause unintended invocation, leading the agent to activate the skill in contexts where it is not appropriate and potentially override more suitable behavior or user intent.

Natural-Language Policy Violations

Medium
Confidence
83% confidence
Finding
The skill is written entirely in Chinese and its output format implicitly fixes behavior to that locale without giving the user a language choice. While not directly a security exploit, this can cause instruction rigidity, reduce usability for other users, and increase the chance of misalignment if invoked unexpectedly in multilingual contexts.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger conditions are broad enough to activate on common questions about industries, policy, or risk, which can cause the skill to engage outside a clearly scoped expert-review context. In an agent system, this increases the chance of overreach, misrouting, or unauthorized policy-style guidance being applied where a narrower skill or neutral response would be safer.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The cycle-analysis triggers are ambiguous and may match many ordinary discussions of downturns, growth, or strategy without defining boundaries for domain, user role, or decision criticality. This can lead the agent to provide authoritative-seeming macro/financial guidance in situations where context is incomplete, increasing the risk of misleading or inappropriate advice.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger conditions for Skill 1 are broad enough to activate on many ordinary business or operations prompts, which can cause the agent to invoke this specialized strategic framework unexpectedly. Over-broad routing increases the chance of scope hijacking, irrelevant guidance, or unreviewed decision-support outputs being applied in contexts where the user did not explicitly request this mode.

Vague Triggers

Medium
Confidence
84% confidence
Finding
Skill 2 uses vague activation criteria around competition analysis and strategic positioning, so it may be selected for a wide range of generic business discussions without clear user consent. In an agentic system, ambiguous activation can lead to unintended strategic framing, overconfident competitive advice, or policy-bypassing behavior if the skill becomes the default path for loosely related prompts.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger conditions for '核心冲突提炼' are broad enough that the skill could activate for many generic branding or strategy requests without clear scoping or safety constraints. In this file's context, the skill is explicitly optimized for controversy, emotional manipulation, and memorability over restraint, which increases the chance of unsafe or misaligned marketing guidance being invoked unintentionally.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The social-marketing trigger conditions are similarly overbroad and can be invoked by routine requests about growth, content, or campaigns. Because the skill promotes viral spread, emotional provocation, and controversy as tactics, accidental activation could steer users toward risky amplification strategies without adequate safeguards.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The document repeatedly endorses controversy, '洗脑' repetition, emotional exploitation, and being '被骂比被无视强' without corresponding warnings about reputational harm, manipulation, or ethical constraints. In a skill meant to provide reusable agent reasoning, this normalizes risky persuasion patterns and can lead downstream users or agents to generate unsafe marketing strategies as if they were standard best practice.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The trigger conditions for Skill 1 are broad enough to match many ordinary AI advisory or architecture discussions, which can cause the skill to activate outside its intended scope. In a multi-skill agent, this increases the risk of inappropriate routing, overreach in responses, and inconsistent application of more specialized or safer skills.

Vague Triggers

Medium
Confidence
84% confidence
Finding
Skill 2 uses ambiguous triggers like user concern about maintenance cost or architecture refactoring, which overlap with many general technical consulting requests. This ambiguity can lead to accidental invocation, misclassification of user intent, and advice being generated under the wrong skill context, especially where other governance or compliance-oriented skills should take precedence.

Vague Triggers

Medium
Confidence
92% confidence
Finding
Skill 1's trigger conditions are broad enough to activate on many ordinary product, design, or technical questions, which can cause unintended routing to this persona-specific skill. In a multi-skill agent, overbroad activation increases the chance of inappropriate guidance, unnecessary authority bias, and reduced predictability, especially because the skill presents strong prescriptive methods rather than narrow scoped assistance.

Vague Triggers

Medium
Confidence
89% confidence
Finding
Skill 2 uses ambiguous trigger language around user experience optimization, technical tradeoffs, and cost balancing, all of which are common in ordinary business and product discussions. This weak scoping can make the agent invoke the skill too often, causing misclassification of user intent and over-application of a specific framework where a more appropriate skill or neutral response should be used.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The first skill's trigger conditions are broad enough that the agent may invoke legal-risk analysis in situations where the user only casually mentions risk, contracts, or compliance. Unintended activation can cause the system to apply a strong authority-framed legal workflow outside its intended scope, leading to irrelevant guidance, over-collection of sensitive context, or user confusion in mixed-purpose conversations.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The second skill activates on highly generic conditions like needing compliance training or culture building, which can match many enterprise discussions without a clear request for this specific module. In a committee-style skill pack, such underspecification increases the chance that the legal/compliance persona dominates unrelated workflows, causing misrouting and potentially inappropriate policy-style advice.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger conditions for Skill 1 are broad phrases like '需要优化视觉设计方案' and '设计元素过多/过杂', which can match many unrelated user requests and cause unintended invocation. In an agent system, ambiguous routing can override user intent, apply the wrong expert persona, or expose downstream tools/prompts to contexts where they were not meant to run, even though this file itself contains no obviously malicious payload.

Vague Triggers

Medium
Confidence
88% confidence
Finding
Skill 2 uses similarly expansive triggers such as improving perceived product value or full-sensory brand experience, which are vague enough to activate across a wide range of product, marketing, or strategy conversations. This increases the chance of misrouting and unintended skill execution, especially in a multi-skill environment where overlapping business and design prompts may cause this skill to supersede more appropriate ones.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.