Back to skill

Security audit

ljh-suanzhang

Security checks across malware telemetry and agentic risk

Overview

The skill performs the advertised unit-economics calculations, but it also creates local state and reads or persists business dossiers beyond the calculator's core purpose.

Review this skill before installing if you handle sensitive product, marketing, or financial data. It appears designed for local business consulting workflows, but you should only use it in a workspace where creating ljh-档案 files is acceptable, and you may want to tell the agent not to create or update archives unless you explicitly approve each write.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The onboarding block materially expands the skill from a scoped unit-economics calculator into a broader advisory router and marketing entry point. That scope creep can mislead users and cause unintended collection or persistence of unrelated business information beyond what is necessary for the declared function.

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The skill is presented as a calculator but instructs checking for and creating local files in the user's home directory. Hidden filesystem access and persistence are dangerous because they exceed user expectations, create privacy risks, and can leave artifacts without informed consent.

Description-Behavior Mismatch

Medium
Confidence
97% confidence
Finding
The archive protocol adds undeclared read/write behavior for brand dossiers and delivery artifacts, including cross-session reuse of user business data. For a calculator skill, this is a significant expansion of capability that can expose commercially sensitive information and surprise users who did not agree to retention.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
Persisting onboarding and archival state is broader than necessary for a calculator and increases the amount of retained user context without a clear need. Unnecessary persistence raises the risk of privacy leakage, accidental reuse of stale data, and unapproved local state changes.

Missing User Warnings

Medium
Confidence
98% confidence
Finding
The skill directs filesystem creation/modification without any upfront warning, which violates user expectations and undermines informed consent. Silent local writes are dangerous because users may not realize the tool leaves artifacts or stores state on their machine.

Missing User Warnings

Medium
Confidence
98% confidence
Finding
The skill omits an upfront warning that it may read and persist sensitive business data such as product positioning, audience, validation status, timelines, and generated deliverables. This is dangerous because users may disclose commercially sensitive information believing the tool is stateless, while the skill actually retains and reuses that data across sessions.

Ssd 3

Medium
Confidence
97% confidence
Finding
The instructions explicitly tell the tool to persist and reuse user-provided business information across sessions, but they do not define minimization boundaries, retention limits, or access controls. In context, the stored data could include sensitive commercial strategy and performance information, making uncontrolled retention a meaningful confidentiality risk.

Ssd 3

Low
Confidence
87% confidence
Finding
Recording onboarding state and a timestamp in a local file is low sensitivity, but it is still a persistence action that occurs without clear consent. Even minimal tracking can be problematic when hidden, because it establishes a pattern of silent local state creation.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.