Back to skill

Security audit

ljh-daren

Security checks across malware telemetry and agentic risk

Overview

The skill mainly provides influencer account screening, but it also performs automatic local persistence, reads and writes business archive files, and displays unrelated promotional contact information.

Review this before installing if you do not want the agent to create local state or keep business diagnosis records on disk. The core screening logic is not malicious, but users should be aware that it may read and update ljh-档案 files in the working directory, create an onboarding marker in the home directory, and show off-platform contact handles.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Description-Behavior Mismatch

Medium
Confidence
97% confidence
Finding
The skill is presented as an influencer diagnosis tool, but its first-run behavior injects unrelated onboarding, broader business consulting options, and off-task promotion before handling the user's request. This violates least surprise and can divert users into disclosing additional business information unrelated to the stated purpose.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The documentation instructs the skill to create local state files on first use and later manage archive files, despite the skill being described as a diagnosis-only tool. Hidden persistence expands the skill's effective capabilities and creates privacy and data-retention risk beyond what users would reasonably expect from the manifest.

Context-Inappropriate Capability

Low
Confidence
92% confidence
Finding
The onboarding message includes off-platform contact identifiers for a user group that are not needed to perform influencer account screening. Unnecessary sharing or solicitation of external contact channels can facilitate unwanted outreach, phishing surface expansion, or policy bypass outside the audited environment.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger phrases are broad natural-language requests that could match common conversation and cause the skill to activate when the user did not intend to invoke it. Because the skill also performs persistence and onboarding side effects, accidental activation increases the chance of unexpected file writes and unrelated data collection.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill directs creation of local files on first use without a clear upfront user-facing warning and consent gate before persistence occurs. This undermines informed consent and can lead users to unknowingly store business data and timestamps on disk.

Ssd 3

Medium
Confidence
98% confidence
Finding
The skill instructs persistent storage of user-provided business data, conclusions, and deliverables across interactions in local archive files. Cross-session retention of potentially sensitive commercial information increases exposure to unauthorized access, unintended reuse, and overcollection relative to the immediate screening task.

Ssd 3

Medium
Confidence
93% confidence
Finding
The mandatory first-run onboarding exposes personal contact identifiers to every new user regardless of need or consent. Broadcasting direct personal contact details inside operational workflow is unnecessary for the skill's purpose and increases privacy, harassment, and impersonation risk.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.