Market Analysis CN | 市场分析服务

Security checks across malware telemetry and agentic risk

Overview

This skill is a simple paid market-analysis service description with no code, credentials, persistence, or hidden system access.

Before installing, confirm the provider and pricing, and only share business, market, or customer-behavior data that you intentionally want analyzed. Be aware that generic phrases like “market analysis” or “趋势” may trigger this skill in broad business conversations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases include very broad terms such as '市场分析', '竞品分析', 'market analysis', and '趋势', which are common in normal business conversations and can cause unintended invocation. This increases the chance that the skill activates outside clear user intent, leading to misleading routing, unwanted paid-service promotion, or inappropriate handling of unrelated requests.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal