Back to skill

Security audit

ljh-yinzi

Security checks across malware telemetry and agentic risk

Overview

The skill is a content-analysis advisor with some local note-taking behavior, but it does not show exfiltration, credential use, destructive actions, or hidden execution.

Install only if you are comfortable with the skill keeping local business notes. Review or delete ~/.ljhskill/onboarding.json and any ljh-档案 folder if you do not want cross-session state, and avoid using it in shared workspaces with sensitive brand, spend, ROI, or customer-positioning data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill is presented as a content-factor analysis tool, but its first-run behavior injects unrelated product, content, and business-diagnosis onboarding plus community contact details. This creates a scope mismatch that can mislead users and cause unintended disclosure of additional business information beyond the requested task.

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The skill description suggests an advisory toolkit, but the body instructs the agent to read and write local state files for onboarding and later persistence. That is broader than users would reasonably expect from the manifest and can surprise users with hidden statefulness and filesystem access.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
The onboarding advertises unrelated business-diagnosis capabilities that do not align with a content-factor toolkit. This broadens the apparent authority of the skill and can steer users into sharing unnecessary sensitive operational or commercial information.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill instructs silent creation of onboarding and archive files without a clear up-front warning in the user-facing description. Hidden persistence undermines informed consent and can expose local data or create compliance issues in shared or sensitive environments.

Ssd 3

Medium
Confidence
98% confidence
Finding
The skill directs the agent to persist brand profile information, user/business context, conclusions, and deliverables across sessions in local files, with reuse in future interactions. Without clear data-minimization limits, retention periods, or sensitivity boundaries, this can accumulate commercially sensitive information and increase the blast radius of any local compromise.

Ssd 3

Low
Confidence
93% confidence
Finding
Recording first-use state in a local onboarding file is a form of persistent tracking, even if limited. While low severity, it still creates undeclared state across sessions and may be undesirable in privacy-sensitive or multi-user environments.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.