Back to skill

Security audit

文献综述迭代诊断

Security checks across malware telemetry and agentic risk

Overview

This is a text-only academic literature review feedback skill with no code, persistence, credential access, or hidden system changes.

Safe to install for literature review feedback. Avoid submitting confidential or unpublished research unless you are comfortable sharing it with the model, and manually verify any bibliography existence or journal-quality claims against authoritative academic databases.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger list includes broad, conversational phrases like “帮我看看这篇综述有什么问题”, which can overlap with ordinary user requests and cause the skill to activate when the user did not explicitly seek this specialized workflow. Misrouting is not a code-execution issue, but it can cause unintended handling of user input, reduce reliability, and expose users to an overly rigid analysis flow without clear consent.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.