Back to skill

Security audit

ljh

Security checks across malware telemetry and agentic risk

Overview

The skill is a coherent product-launch router, but it can automatically run linked workflows and persist business dossiers without clear upfront opt-in.

Install only if you are comfortable with the skill routing you directly into other LJH workflows and saving product-launch notes locally. Before using guided mode, decide whether you want the ljh-档案 dossier; say clearly that you do not want a dossier if the product, pricing, campaign, or creator information is sensitive.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The skill claims to be only a routing entry point, but it instructs the agent to create persistent onboarding and dossier files under the user's home/workspace. This creates hidden state and data retention beyond what a user would reasonably expect from a router, increasing privacy risk and making later behavior dependent on undeclared local artifacts.

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The document says the skill only routes and does not perform diagnosis or analysis, but later directs it to inline-run full downstream tool workflows. That mismatch can cause the agent to exceed its declared scope and inherit powerful behavior from other tools without clear user awareness or consent.

Intent-Code Divergence

High
Confidence
95% confidence
Finding
Although framed as a simple router, the instructions require the skill to execute downstream tools, manage archival state, and coordinate multi-step workflow progression. This is dangerous because it effectively turns a low-privilege dispatcher into an orchestrator with broader authority, amplifying the blast radius of mistakes or prompt injection in linked tools.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The trigger phrases include broad natural-language requests such as 'help me launch this product' and 'what should I do next,' which can overlap with ordinary business advice conversations. Over-broad activation can cause the skill to engage unexpectedly, leading to unsolicited routing, file operations, or stateful workflow behavior in contexts where the user did not intend to invoke this capability.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill performs persistent local file creation for onboarding and ongoing dossier/artifact writes, but the user-facing description does not clearly warn about that storage behavior. Hidden persistence is a security and privacy issue because users may disclose commercial or personal information without understanding that it will be archived locally across sessions.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.