Back to skill

Security audit

外贸文案全能助手|31语种·全场景

Security checks across malware telemetry and agentic risk

Overview

This is a static foreign-trade writing assistant with broad activation wording but no hidden execution, persistence, credential access, or destructive behavior.

Installers should know this skill may be invoked by a generic Chinese phrase for writing an email, so review generated output when the request is not about foreign trade. Also verify any business, legal, certification, or market claims before sending them externally.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger at line 24 is the broad phrase "写封邮件" ("write an email"), which can match many ordinary user requests unrelated to foreign trade. Overly generic activation terms increase the chance this skill is invoked outside its intended scope, causing untrusted content or business-oriented instructions to be injected into unrelated conversations.

Vague Triggers

Low
Confidence
83% confidence
Finding
The description claims broad end-to-end capabilities across many trade-writing scenarios and languages, but does not define clear boundaries for when the skill should activate. This can widen match behavior and create ambiguity about scope, which compounds the risk of accidental invocation when combined with broad triggers.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.