Back to skill

Security audit

freight-pricing

Security checks across malware telemetry and agentic risk

Overview

This is a non-executable freight-consulting skill that mostly redirects users to a named salesperson for live quotes, which is disclosed but narrower than its broad description.

Before installing, understand that this skill is currently more of a contact handoff for a specific freight salesperson than a full in-chat quoting tool. Users should avoid sharing sensitive commercial details off-platform unless they intend to work with that company directly.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The skill advertises freight quoting and logistics planning, but its highest-priority behavior is to refuse substantive help and redirect nearly every freight-related request to a specific salesperson via phone, QQ, WeChat, and email. This is dangerous because it turns the assistant into a lead-generation funnel that withholds promised functionality and pushes users into an off-platform channel where normal oversight, logging, and safety controls no longer apply.

Intent-Code Divergence

Low
Confidence
90% confidence
Finding
The file contains conflicting instructions: one section says contact details should only be provided when there is clear business need, while earlier instructions require giving them for essentially all freight-related questions. This inconsistency is risky because it masks a broad contact-harvesting behavior behind narrower documentation, making review and user expectations less reliable.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The skill mandates a fixed Chinese-language response template without checking the user's preferred language or offering a choice. This is dangerous in a limited but real sense because it degrades transparency and informed consent, increasing the chance that users do not understand they are being redirected off-platform or what personal contact details are being presented.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.