V2ex Hot Cn

Security checks across malware telemetry and agentic risk

Overview

This skill is low risk, but it appears to show built-in sample V2EX topics rather than live community data.

Installers should understand that this skill appears safe from a security perspective, but its output may not be current V2EX data unless the publisher updates it to fetch live topics or clearly labels the results as sample data. Consider narrowing or disabling broad triggers like "v2" if accidental activation would be annoying.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger phrases include generic terms like "V2EX", "v2", and "程序员社区", which can appear in normal user conversation and may cause unintended activation of the skill. This can hijack requests that merely mention the community rather than explicitly asking to use the skill, leading to incorrect routing or unnecessary external lookups.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal