Back to skill

Security audit

weekly-report

Security checks across malware telemetry and agentic risk

Overview

This is a prompt-only weekly report writing skill with no hidden code execution, data access, or installation behavior beyond user-provided work status details.

Before installing, consider whether your project names, risks, customer details, and weekly status notes are appropriate to share with the AI client you use. Review any field marked 【推断】 before sending the report, because those parts are not confirmed facts.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill promises '绝不编造' in its manifest, but later permits inferred project assignment and simulated user answers under some conditions. This creates a trust-boundary mismatch: users or downstream systems may rely on a no-fabrication guarantee while the skill can still introduce model-generated content, increasing the risk of inaccurate reporting being presented as factual.

Intent-Code Divergence

Medium
Confidence
96% confidence
Finding
The documentation states that every word must come from the project library or user input, yet later instructions allow the model to infer missing details when the user refuses to answer. This inconsistency can mislead users into overtrusting generated weekly reports, causing hallucinated risks, plans, or judgments to be treated as real workplace status updates.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.