Back to skill

Security audit

Wanpaike Opc Business Model Analysis

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed business-model analysis prompt with no executable code, persistence, credential use, or hidden data movement.

Install this only if you are comfortable sharing business model details, pricing, costs, customer segments, and validation status with the agent using the skill. Non-Chinese users should confirm they can understand the prompts and outputs before relying on the analysis.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger conditions are broad and overlap with common business-advice requests such as designing, optimizing, evaluating, or comparing a business model. In an agent platform, this can cause unintended invocation on loosely related conversations, leading to surprise activation, irrelevant data collection prompts, and increased exposure of user business information to a skill they did not explicitly choose.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The skill is written entirely in Chinese and does not specify any language negotiation or fallback behavior. This can cause incorrect or opaque responses for users operating in other languages, increasing the chance of misunderstanding analytical output or providing sensitive business data without fully understanding the workflow.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.