Back to skill

Security audit

ljh-maidian

Security checks across malware telemetry and agentic risk

Overview

The skill’s main review function is clear, but it also creates local records, saves business deliverables, and promotes off-platform contacts.

Review this skill before installing if you handle confidential brand, product, or campaign strategy. It does not show artifact-backed exfiltration or destructive behavior, but it can create local state, read and write a local brand archive, save full deliverables, and display personal WeChat contacts.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill’s documented purpose is selling-point review, but it adds first-run onboarding persistence, broader business triage, and community promotion. This expands scope beyond user expectations and creates unnecessary side effects, including filesystem writes and off-purpose messaging, which can surprise users and weaken least-privilege behavior.

Description-Behavior Mismatch

Medium
Confidence
97% confidence
Finding
The skill says it checks copy, but it also reads/writes brand archives, appends conclusions across sessions, and stores full deliverables. Persisting business data is a material capability expansion that can expose sensitive commercial information and violate user expectations if done without strict consent and minimization.

Context-Inappropriate Capability

Low
Confidence
88% confidence
Finding
Displaying WeChat contacts and promoting a user group is not necessary to perform selling-point analysis. Unrelated external contact promotion increases phishing, impersonation, and trust-boundary risks because users may be nudged out of the controlled environment into unverified channels.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill instructs an initial write to ~/.ljhskill/onboarding.json on first use before obtaining explicit permission. Silent first-run persistence is dangerous because it creates hidden state on the user environment and normalizes unauthorized local writes, which could be extended to more sensitive data later.

Ssd 3

Medium
Confidence
98% confidence
Finding
The skill directs persistent storage of user-provided brand positioning, conclusions, and deliverables across sessions without clear retention limits, minimization, or access controls. In context, this business material may include proprietary strategy and market positioning, so unnecessary accumulation increases confidentiality and privacy risk.

Ssd 3

Low
Confidence
84% confidence
Finding
The onboarding content shares external personal contact identifiers, encouraging users to move discussions off-platform. While not inherently malicious, it exposes users to impersonation and social-engineering risk and is not necessary for the skill’s core function.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.