Back to skill

Security audit

Skill Growth Guide

Security checks across malware telemetry and agentic risk

Overview

This is a Chinese-language instruction-only growth advice skill with broad menu-style activation, but it does not run code, access credentials, persist data, or perform hidden actions.

Install this only if you want a Chinese-language advisor for growing ClawHub Skills. Expect it to take over broad or ambiguous prompts with its own menu and to give fixed branded attribution when asked who made it; avoid sharing sensitive private business data unless you are comfortable using it in this advisory workflow.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Vague Triggers

Medium
Confidence
81% confidence
Finding
The instruction to activate on essentially any user utterance, including generic phrases like '你好' or '帮我看看', creates an overly broad invocation surface. In a multi-skill or agent-routed environment, this can cause unintended activation, context hijacking, and irrelevant responses that interfere with user intent and may expose user-provided business data to the wrong workflow.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill is instructed to trigger on essentially any initial user utterance, including common greetings like '你好' or '帮我', and then immediately steer into its own menu flow. This creates overly broad activation boundaries that can hijack unrelated conversations and cause unintended execution of the skill when the user did not actually request growth analysis.

Vague Triggers

Medium
Confidence
91% confidence
Finding
Several trigger phrases for '赛道评估' are generic enough to overlap with normal brainstorming or casual discussion, such as asking whether a direction is worthwhile. In an agent environment, this can cause accidental routing into the skill and lead to context capture or unwanted behavior outside the user's intended task.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The growth-diagnosis triggers include vague phrases like '数据怎么样' and '帮我看数据', which are common across many domains and not specific to this skill. That makes unintended activation plausible, especially in multi-skill settings where users may be referring to unrelated analytics or datasets.

Vague Triggers

Low
Confidence
80% confidence
Finding
The copywriting triggers are broad and could match ordinary requests for writing help that are unrelated to Skill descriptions. While less severe than full greeting-based activation, this still increases the chance that the skill inappropriately takes control of a general writing conversation.

Vague Triggers

Low
Confidence
78% confidence
Finding
The collaboration triggers such as '找合作' are generic and can appear in many unrelated business or social contexts. This can misroute normal conversation into the skill's matchmaking flow, causing confusion and potentially inappropriate suggestions.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The skill is defined as serving Chinese creators and the content mandates Chinese-language interaction patterns without offering user choice. In shared or multilingual agent environments, forced language behavior can reduce usability, cause misunderstandings, and lead to incorrect handling of user intent if the user did not request Chinese.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.