Back to skill

Security audit

Enforcement Assistant

Security checks across malware telemetry and agentic risk

Overview

This is a static legal-procedure skill for China civil enforcement, with no executable behavior, but users should handle debtor and applicant personal data carefully.

Install only if you need China civil enforcement filing help. Treat it as procedural template assistance, not legal advice; verify court requirements and deadlines with a lawyer or the court, collect only lawfully obtained and necessary personal or financial information, and avoid sharing full IDs, addresses, or asset details outside official or secure channels.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Context-Inappropriate Capability

Medium
Confidence
88% confidence
Finding
The guidance explicitly recommends using '财产调查公司' and '征信机构' to gather debtor asset information, which can encourage users to obtain sensitive personal and financial data through third-party investigative channels outside narrow court-supervised procedure. In a legal-enforcement guidance skill, that broadens the scope from neutral process assistance into potentially privacy-invasive operational advice and could facilitate misuse or unlawful data collection.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger examples are broad, generic legal-help phrases that can cause the skill to activate for routine legal questions without clear boundaries on when it should defer, disclaim limits, or ask jurisdiction/scope clarifying questions. In a legal-assistance context, overbroad activation increases the chance of the system providing procedural guidance in situations outside its intended scope, which can mislead users or bypass safer routing to qualified counsel.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The usage triggers include broad phrases such as "对方欠钱不还申请执行" and especially scenario content that discusses suing before any enforceable instrument exists, which can cause the skill to activate outside its stated post-judgment enforcement scope. In a legal-procedure skill, this mismatch can route users into the wrong workflow, producing inaccurate procedural guidance and potentially causing missed deadlines or improper filings.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The template explicitly requests highly sensitive personal data such as ID numbers, home addresses, and phone numbers, but provides no privacy minimization, redaction, storage, or transmission guidance. In a legal-assistance skill this can lead users to over-collect or expose personal data in unsafe channels, increasing the risk of privacy breaches, identity theft, and unauthorized disclosure.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The document provides extensive instructions for collecting bank, property, vehicle, social-relationship, and other asset clues from many sources, but the privacy and legality warning appears much later and is not prominent near the collection guidance. That omission can normalize broad gathering of highly sensitive personal data and make users more likely to overcollect, misuse, or unlawfully obtain information under the guise of enforcement preparation.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.