Back to skill

Security audit

ljh-xuanpin

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly a product-selection advisor, but it adds under-disclosed persistent file writes, business-data archiving, and onboarding/promotional behavior that users should review first.

Install only if you are comfortable with the skill reading and writing local business-analysis files and using broad product-selection triggers. Review where it stores dossiers and reports, avoid sharing sensitive competitor/customer data unless authorized, and prefer explicit /ljh-xuanpin invocation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The skill is presented as a narrow product-selection tool, but its first-run behavior injects onboarding, promotion of external contact channels, and broader service routing before handling the user's request. This creates scope creep and violates least surprise: a user invoking a focused analysis skill may instead trigger unrelated messaging and side effects, increasing the chance of unintended disclosure or manipulation.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The skill expands from advisory analysis into persistent file-based CRM/knowledge management by reading and writing brand dossiers and delivery artifacts in the working directory. Persistent storage of user-supplied business data without explicit, up-front consent and clear boundaries can leak sensitive information across sessions, tools, or users in shared environments.

Intent-Code Divergence

Medium
Confidence
86% confidence
Finding
The document claims the tool only judges whether a candidate product is worth pursuing, yet the earlier onboarding routes users into content and operations diagnosis. This inconsistency can cause the agent to perform actions or collect information outside the user's intended scope, undermining informed consent and predictable behavior.

Vague Triggers

Medium
Confidence
84% confidence
Finding
Broad natural-language triggers such as 'judge this product candidate' or '选品怎么判断' are likely to match ordinary conversation, causing accidental activation in contexts the user did not intend. Because the skill can request substantial business data and initiate file-related behavior, unintended triggering raises privacy and safety risk beyond a harmless UX issue.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs creation of ~/.ljhskill/onboarding.json on first use and does so before handling the user's request, but the user-facing description does not disclose that local files will be written. Undisclosed filesystem writes are dangerous because they create persistent state, can surprise users in sensitive environments, and may violate platform expectations for consent and data minimization.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill instructs collecting and exporting third-party comment data from e-commerce platforms or external analytics tools without any warning about privacy, terms-of-service, or handling of potentially personal data. Even if the data is commercially useful, normalizing bulk extraction without safeguards can lead to improper processing or policy violations.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.