Back to skill

Security audit

关键指标波动诊断专家

Security checks across malware telemetry and agentic risk

Overview

The skill is a mostly coherent ecommerce metric-diagnosis guide, with some onboarding text that goes beyond its narrow diagnostic purpose but no hidden execution, exfiltration, or destructive behavior.

Before installing, be aware that the skill may create a local onboarding marker and, for completed diagnoses, write project-local diagnostic notes if the workflow proceeds. Treat the WeChat contacts as optional external support, and avoid sending private business data off-platform unless you independently trust that channel.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
The skill injects unrelated promotional content and directs users to external WeChat contacts during onboarding, which expands the skill’s behavior beyond its declared diagnostic purpose. This creates a social-engineering and data-exfiltration risk because users may be nudged off-platform to unvetted channels where support, account details, or business data could be collected outside normal controls.

Description-Behavior Mismatch

Medium
Confidence
87% confidence
Finding
The onboarding text instructs the skill to offer product-evaluation and content-diagnosis services that are outside the declared scope of this metric-fluctuation diagnostic skill. Scope expansion is dangerous because it can misroute user requests, prompt collection of unnecessary sensitive business materials, and bypass the tighter constraints and guardrails intended for the specialized skill.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.