Back to skill

Security audit

ljh-koc

Security checks across malware telemetry and agentic risk

Overview

This skill should be reviewed because it goes beyond KOC report guidance by writing persistent local files and advertising personal WeChat contacts.

Install only if you are comfortable with the skill reading a local brand archive and storing KOC conclusions or reports in your working directory. Do not share confidential business information through the listed personal WeChat contacts unless that is an approved channel for your team.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The skill metadata advertises a narrow KOC validation function, but the body adds onboarding, broad business-triage prompts, and promotion of external community contacts. This scope expansion can mislead users and security reviewers about what the skill will do, increasing the chance of unexpected data collection or off-platform redirection.

Description-Behavior Mismatch

Medium
Confidence
98% confidence
Finding
The skill claims its task is limited to KOC validation, yet it also reads, creates, appends, and stores cross-tool brand archives and deliverables on disk. This is a material capability expansion because persistent file operations can retain sensitive business data beyond the immediate session without clear upfront disclosure.

Context-Inappropriate Capability

Medium
Confidence
97% confidence
Finding
The onboarding message advertises personal WeChat contact details unrelated to the core KOC validation function. Redirecting users to personal contact channels can facilitate unauthorized data sharing, social engineering, or movement of sensitive business discussions outside governed platform controls.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs creating a local onboarding state file on first run, but the description does not warn users that local files may be written. Undisclosed persistence undermines informed consent and can create unexpected tracking of usage state on the host environment.

Missing User Warnings

Medium
Confidence
98% confidence
Finding
The skill proposes creating and appending brand archive files and saving deliverables locally without upfront disclosure in the skill description. Because the archived content may include product, strategy, and performance data, silent writes materially increase privacy and data-governance risk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.