Bigyou

Security checks across malware telemetry and agentic risk

Overview

This is a local Chinese decision-support skill for comparing options, with no hidden access, network behavior, or persistence found.

Install if you want a Chinese-language helper for comparing options. Be aware it may activate on broad choice phrases like “which is better” or “how should I choose,” and its scoring is heuristic, so verify facts and use extra care for high-stakes career, finance, investment, housing, or medical decisions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The README uses very broad trigger phrases like “哪个好”, “怎么选”, and “A还是B”, which overlap heavily with ordinary conversation and can cause the skill to activate in many unrelated contexts. That increases the chance of unintended invocation, context hijacking, or the skill intercepting requests better handled by more specialized agents, especially because decision/comparison language is common across many domains.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The activation description and trigger phrases are broad enough to match common conversational language such as asking for comparisons or saying one is conflicted. This can cause unintended invocation in unrelated contexts, leading the skill to take over conversations where structured decision support was not requested, which may skew responses or expose users to inappropriate guidance in sensitive domains like jobs, finance, or investments.

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal