Back to skill

Security audit

ljh-qianchuan

Security checks across malware telemetry and agentic risk

Overview

The skill is not clearly malicious, but it needs Review because it expands beyond its advertised diagnostic purpose and uses persistent local files without enough upfront disclosure.

Install only if you are comfortable with the skill creating a first-use marker in your home directory, reading and updating a local brand archive in the working directory, and saving business diagnostic outputs for later reuse. Use it in a dedicated project folder and tell the agent not to create or update archives if you do not want persistent records. Treat the displayed WeChat contacts as off-platform support information, not as required for the diagnostic flow.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill’s behavior exceeds its stated purpose of a narrow Qianchuan traffic-drop diagnostic flow by injecting a first-run onboarding experience and broader product/content/business consulting options. This scope expansion can surprise users, increase unintended data collection, and create opportunities for the skill to steer users into unrelated workflows or disclosures not covered by the manifest description.

Description-Behavior Mismatch

Medium
Confidence
98% confidence
Finding
The skill checks for and creates a persistent onboarding file in the user’s home directory without clear upfront consent in the manifest or initial user-facing warning. Undisclosed cross-session persistence is dangerous because it modifies the local environment, creates tracking state, and may violate user expectations about stateless tool behavior.

Description-Behavior Mismatch

Medium
Confidence
98% confidence
Finding
The skill instructs the assistant to read and write brand archives and delivery artifacts in the current directory, including appending conclusions and storing full outputs across sessions. This creates undisclosed persistent storage of potentially sensitive business information and can lead to accidental retention, data leakage, or modification of local files beyond the user’s immediate request.

Missing User Warnings

Medium
Confidence
99% confidence
Finding
The skill description embeds automatic local file reads/writes but does not prominently warn users that it will modify the filesystem. Hidden file operations are risky because users may unknowingly permit persistence, and an agent operating in different environments could create or overwrite files in sensitive locations.

Missing User Warnings

Medium
Confidence
99% confidence
Finding
The archive protocol directs file creation and updates in the current directory without a clear warning or explicit confirmation at the point of use. Writing in the current directory is especially risky because the working directory may vary, causing unintended modification of project files or storage of sensitive business records in inappropriate locations.

Ssd 3

Medium
Confidence
89% confidence
Finding
The onboarding text instructs the assistant to publish direct personal contact identifiers for off-platform communication. Even if intended as support information, this increases privacy and trust risks by encouraging unsolicited contact and creating a channel for social engineering outside the monitored platform.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.