Back to skill

Security audit

ljh-dingwei

Security checks across malware telemetry and agentic risk

Overview

The skill is a mostly coherent product-positioning helper, but it automatically creates local state and can read or write brand archive files containing sensitive business information.

Review before installing if you work with confidential product or brand strategy. The skill may create a first-run marker in your home directory and may reuse or update ljh-档案 files in the working directory; tell the agent not to create or update archives if you want a no-persistence session.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The skill is presented as a positioning one-pager generator, but it also performs onboarding-state checks and writes a persistent file under the user's home directory. That is behavior outside the core task and creates undisclosed statefulness and filesystem side effects, which can surprise users and leak usage metadata across sessions.

Description-Behavior Mismatch

Medium
Confidence
98% confidence
Finding
The skill silently reads and writes brand archives and delivery artifacts in the working directory, but this storage behavior is not reflected in the top-level description. Hidden data collection and persistence can expose sensitive commercial information and cause users to disclose more than intended under the assumption the tool only generates a document.

Context-Inappropriate Capability

Low
Confidence
89% confidence
Finding
The onboarding flow injects external promotional content and personal contact identifiers unrelated to the requested positioning task. This creates unnecessary data exposure and trust-manipulation risk, especially because it is shown to first-time users automatically rather than in response to a help or support request.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill attempts to create an onboarding marker file on first use without first warning the user or asking permission. Unconsented file writes are dangerous because they create persistent state, may violate least-surprise expectations, and can fail unpredictably depending on environment permissions.

Missing User Warnings

Medium
Confidence
98% confidence
Finding
The archive workflow reads prior files and writes updated brand records and deliverables without an upfront warning at invocation time. Because these files may contain sensitive business strategy, product positioning, and customer information, silent persistence materially increases confidentiality and privacy risk.

Ssd 3

Medium
Confidence
95% confidence
Finding
The first-run onboarding automatically displays personal contact identifiers to all users, regardless of whether they requested support. This unnecessarily distributes personal contact data and can be abused for unsolicited contact, social engineering, or trust bootstrapping unrelated to the skill's stated purpose.

Session Persistence

Medium
Category
Rogue Agent
Content
新品定位一页纸生成器。喂产品资料,产出六栏定位一页纸:定位一句话、价值四象限、必要项与差异项、竞争差异、翻译成内容、双重校验。
  触发方式:/ljh-dingwei、「帮我写一份产品定位」「这个新品怎么定位」「填一下定位一页纸」「这个品的心智句怎么收」
  New-product positioning one-pager generator. Feed in product materials and get a filled six-column positioning sheet with a value quadrant and validation checks.
  Trigger: /ljh-dingwei, "write a product positioning", "fill the positioning one-pager", "help me define this new product"
  企业战略定位、城市品牌定位这类通用定位场景,不要自动触发。
---
Confidence
83% confidence
Finding
write a product positioning", "fill the positioning one-pager", "help me define this new product" 企业战略定位、城市品牌定位这类通用定位场景,不要自动触发。 --- # 新手引导(首次必读) 本工具首次使用时,检查 `~/.ljhskill

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.