Back to skill

Security audit

LJH 商详页说服地图

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed product-detail strategy assistant with limited, purpose-related local note keeping, not evidence of malware or deception.

Before installing, be aware that the skill may create a small onboarding marker in your home directory and may read or update ljh-档案 files in the current project to reuse and save brand-strategy conclusions. Use it in the intended project directory, and tell the agent not to use archives if you do not want local persistence.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill is presented as a strategy/content-mapping assistant, but it also instructs the agent to create onboarding state files under the user's home directory. That introduces persistence and host-side file modification unrelated to the declared function, which violates least privilege and can surprise users or be abused for unauthorized state tracking.

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The skill claims non-strategy tasks should not auto-trigger, yet it directs reading and writing archive files in the current directory and persisting conclusions over time. This expands behavior from content generation into filesystem access and ongoing state mutation, creating risk of unintended file modification and privacy leakage across sessions/projects.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill instructs file creation without an upfront user-facing warning that local files will be modified. Hidden writes reduce informed consent and can lead to unexpected persistence in sensitive environments, especially because the path includes the user's home directory.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill directs reading and writing project archive files in the working directory without prominent disclosure that it will inspect and modify local project data. In agent environments, such behavior can affect unrelated files, persist sensitive business information, and create confusing side effects beyond the expected strategy output.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.