Back to skill

Security audit

胡田-OPC导师-行业分析

Security checks across malware telemetry and agentic risk

Overview

This is a coherent Chinese industry-research report skill with no executable code, hidden persistence, credential handling, or destructive behavior.

Install this if you want a structured Chinese-language industry analysis workflow. Be aware it may activate for broad market-research prompts and may use external web research sources, so clearly state the industry, scope, preferred language, and output format when using it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger description is extremely broad, covering generic requests like industry analysis, market research, and reports, which can cause the skill to activate for many ordinary user intents outside its narrow intended scope. This increases the chance of inappropriate tool selection, unintended routing, and disclosure of internal workflow or file-generation behavior in contexts where the user did not actually request this specialized skill.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.