Online-to-Offline-O2O-marketing

Security checks across malware telemetry and agentic risk

Overview

This is a single-file O2O marketing advice skill with no code execution, credentials, persistence, or hidden system access.

Safe to install for O2O marketing guidance. Because it may use web search for current examples, avoid including confidential business plans, customer data, internal metrics, or private partner details in prompts that could be turned into search queries. If it activates on generic terms like QR codes, LBS, or private-domain marketing when you did not want O2O advice, ignore or disable it for that task.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill declares very broad trigger terms such as '线上线下', '全渠道', '二维码', 'LBS', and '私域', which are common across many general business and marketing discussions. This can cause unintended invocation outside the author's intended O2O-specific context, leading to irrelevant guidance, context hijacking of unrelated tasks, or accidental routing to a network-enabled skill.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal