Back to skill

Security audit

Procurement Admission Copilot

Security checks across malware telemetry and agentic risk

Overview

This is a read-only procurement review skill that structures supplier materials and flags gaps, with a wording ambiguity around “admission-ready” that users should treat as checklist status, not approval.

Install only if you are comfortable giving the agent access to procurement and supplier documents. Require human reviewers to interpret “ready” as a completeness and issue-status signal, not as approval to admit a supplier, and keep final admission decisions in a separate human-owned process.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The template introduces a binary '是否准入就绪' (admission-ready yes/no) field even though the skill description says it should only structure materials and flag issues for human decision-makers. In a shadow-mode procurement workflow, this can function as an implicit admission recommendation, creating automation bias and potentially bypassing the intended human judgment boundary.

Intent-Code Divergence

High
Confidence
97% confidence
Finding
The header explicitly states the package contains no admission conclusion, but the later '是否准入就绪:是/否' field contradicts that promise. This inconsistency is dangerous because it can mislead operators and auditors about the skill's scope while still eliciting a de facto eligibility determination, increasing the chance of unauthorized or unreviewed procurement decisions.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.