Back to skill

Security audit

ljh-duiqi

Security checks across malware telemetry and agentic risk

Overview

The skill’s main purpose is coherent, but it includes automatic local persistence and reuse of business archives that users should review before installing.

Install only if you are comfortable with the skill writing local state and saving brand deliverables. Before use, decide whether to allow ~/.ljhskill/onboarding.json and the current-directory ljh-档案 archive, and avoid placing confidential product strategy in directories where other tools, backups, or users may read it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The skill’s first-run onboarding expands behavior beyond the declared alignment-table generation role into broad product/content/business consulting and external community promotion. This scope creep can mislead users and operators about what the skill does, increasing the chance that users disclose unnecessary business-sensitive information under a narrower manifest expectation.

Description-Behavior Mismatch

Medium
Confidence
98% confidence
Finding
The skill instructs automatic creation of a local onboarding file in the user’s home directory on first use, even though the manifest describes only content generation. Undisclosed persistence of interaction state is risky because it writes to local storage without explicit consent and creates hidden state that can surprise users or leak usage metadata.

Description-Behavior Mismatch

Medium
Confidence
97% confidence
Finding
The archive protocol directs the skill to create brand archives, append conclusions over time, and save deliverables locally, which materially exceeds an output-only generator role. Persisting user-provided commercial information across sessions increases confidentiality and data-retention risk, especially when users may not expect durable local storage.

Missing User Warnings

Medium
Confidence
98% confidence
Finding
The first-use logic describes automatic file creation without an upfront user-facing warning or consent flow. Silent persistence is dangerous because users cannot make an informed decision about local data storage, and even a simple onboarding record can reveal usage patterns or violate expected data-handling boundaries.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The archive instructions tell the agent to create and modify local brand files containing user business information without a clear, prominent warning that outputs may be persisted. This is risky because users may unknowingly leave sensitive commercial plans, positioning, or product claims on disk where other local users, backups, or tools could access them.

Ssd 3

Medium
Confidence
99% confidence
Finding
The onboarding flow persists user interaction state with a timestamp in a hidden home-directory file. Hidden cross-session state is security-relevant because it creates non-obvious tracking/persistence behavior and normalizes file writes outside the narrowly described skill function.

Ssd 3

Medium
Confidence
98% confidence
Finding
The archive protocol reuses, appends, and saves user-provided brand information and deliverables across sessions in local files, creating durable storage of potentially sensitive business data. This can expose confidential marketing strategy, product constraints, and validation status to unintended parties through local access, backups, or later tooling reuse.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.