Back to skill

Security audit

ljh-changjing

Security checks across malware telemetry and agentic risk

Overview

The skill is mainly a business analysis helper, but it automatically creates local state and can persist commercially sensitive brand files with limited user control.

Install only if you are comfortable with local persistence. Before using it with confidential business data, tell the agent whether file storage is allowed, whether it may read or update ljh-档案/品牌档案.md, and whether it should skip the onboarding marker in ~/.ljhskill/onboarding.json. Avoid sharing sensitive GMV, competitor, audience, or positioning details unless the workspace storage policy is acceptable.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (8)

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The skill’s documented behavior exceeds its stated purpose by performing onboarding, promotion, and persistence-related actions before handling the user’s request. This is dangerous because hidden side behaviors can surprise users, widen the trust boundary, and create opportunities for unauthorized data storage or off-task persuasion that the user did not request.

Description-Behavior Mismatch

Low
Confidence
82% confidence
Finding
The metadata says the skill should not auto-trigger for certain broader content-analysis tasks, but the onboarding text invites those exact adjacent use cases. This creates scope confusion that can lead to accidental invocation in contexts where the user did not intend this skill, causing misrouting and over-collection of information.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
Although the skill says it does not handle data pulling, it instructs the agent to create local onboarding state and later manage archive files. Undisclosed file-system side effects are risky because they persist data across sessions and expand the skill’s privileges beyond user-visible analysis.

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
The skill includes promotional external contact information unrelated to the requested analysis task. This is dangerous because it can be used for off-platform funneling, social engineering, or unnecessary exposure of user attention and business context outside the controlled environment.

Vague Triggers

Medium
Confidence
78% confidence
Finding
The trigger phrases overlap with common help-seeking language, increasing the chance of unintended activation. In context, this is more dangerous because the skill also performs persistence and asks for potentially sensitive business data, so accidental triggering can lead to unnecessary collection or file actions.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill directs the agent to create an onboarding file on first use without a clear user-facing warning or consent step. Automatic local persistence is dangerous because users may not expect stateful tracking, and the stored timestamped marker can become part of a broader profile of activity.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill instructs automatic archive creation and ongoing file persistence for brand dossiers and deliverables after task completion. This is dangerous because it stores user-provided business information across sessions without guaranteed review, creating confidentiality, retention, and unauthorized-access risks.

Ssd 3

Medium
Confidence
98% confidence
Finding
The skill explicitly aggregates and stores business fundamentals, audience information, selling points, validation status, timelines, and deliverables for reuse across sessions. In this business-analysis context, that data can be commercially sensitive; persistent collection without strict minimization and consent materially raises privacy and competitive exposure risks.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.