Back to skill

Security audit

ljh-jiaoben

Security checks across malware telemetry and agentic risk

Overview

The skill mainly reviews selling scripts, but it also writes onboarding and archive files and promotes off-platform WeChat contacts in ways users may not expect from the description.

Install only if you are comfortable with the skill reading and writing a local ljh-档案 brand archive and showing WeChat contact information. Avoid pasting confidential scripts unless you explicitly do not want archiving or have checked where the archive files will be stored.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The skill is presented as a selling-script reviewer, but its instructions expand into onboarding, business diagnosis, and promotion of an external user group. This scope creep matters because users and integrators may invoke the skill expecting narrow text analysis while it performs unrelated actions and steers users to off-platform contacts, increasing trust abuse and data-exposure risk.

Description-Behavior Mismatch

Medium
Confidence
97% confidence
Finding
The skill instructs persistent profile management, archiving user-derived conclusions, and saving deliverables to local files, which materially exceeds the stated purpose of reviewing scripts. Hidden persistence is dangerous because it can retain sensitive commercial drafts, marketing strategy, and user-provided business information without clear, informed consent.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
Advertising external WeChat contacts and directing users to add individuals is not necessary for script review and creates an unnecessary off-platform data-sharing channel. This can facilitate social engineering, privacy leakage, and unwanted contact collection under the credibility of the skill.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill directs automatic creation of a local onboarding file on first use, but this behavior is not disclosed up front in the skill description. Undisclosed file writes violate user expectations and can be abused to leave artifacts on the host system without informed consent.

Missing User Warnings

Medium
Confidence
98% confidence
Finding
The skill instructs storing conversation-derived conclusions and full deliverables into persistent archive files without clear prior disclosure. Because users may paste proprietary marketing scripts, customer insights, or business strategy, silent retention increases confidentiality and compliance risk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.