Back to skill

Security audit

Douban Hot Cn

Security checks across malware telemetry and agentic risk

Overview

This Douban movie hot-list skill appears purpose-aligned and low risk, with only a minor routing concern from a broad trigger phrase.

This looks safe to install for Douban/movie hot-list assistance. Expect that it may activate on broad movie-related prompts; if that becomes annoying, narrow the trigger phrases to explicit Douban requests such as "豆瓣热榜" or "豆瓣电影评分".

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
78% confidence
Finding
Overly broad trigger phrases such as generic words like '电影' can cause unintended invocation during normal conversation, leading the agent to activate this skill when the user did not intend it. In an agent ecosystem, this can degrade routing integrity, cause confusing responses, and potentially expose user prompts to the wrong skill context more often than expected.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal