Back to skill

Security audit

Sit Innovation Method

Security checks across malware telemetry and agentic risk

Overview

This is a markdown-only brainstorming skill for SIT innovation methods, with no executable behavior or sensitive access.

Install this if you want a Chinese-language SIT innovation framework for structured ideation. Be aware it may be selected for broad innovation or brainstorming prompts, so users may need to ask for a different method when SIT is not desired.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger description is extremely broad and overlaps with common phrases like 'innovation', 'brainstorming', and 'thinking tools', which can cause the skill to activate outside its intended niche. Over-broad routing can hijack unrelated user requests, degrade instruction fidelity, and increase the chance that this skill inappropriately handles prompts better served by another tool or by the base assistant.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The skill metadata and description indicate a Chinese-only usage expectation, which can force language output regardless of the user's preference or platform policy. This creates policy and usability risk by overriding user language choice, potentially causing incorrect assistance, exclusion of users, or noncompliance with multilingual interaction requirements.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.