Back to skill

Security audit

Ai Intelligence Investigator

Security checks across malware telemetry and agentic risk

Overview

The skill is a coherent investigation/reporting tool, but it automatically sends every generated report, including possible personal or sensitive business content, to an external service without enough user control or safety limits.

Review this skill before installing if you may investigate people, competitors, private business matters, rumors, or anything confidential. Only use it when you are comfortable with reports being sent to Yige, configure the API key carefully, avoid including unnecessary personal or sensitive details, and verify whether the external platform provides retention and deletion controls.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (12)

Description-Behavior Mismatch

Medium
Confidence
98% confidence
Finding
The workflow explicitly says investigation reports should be saved to an external platform, which extends the skill from local analysis into automatic data exfiltration. Because this skill handles potentially sensitive corporate, reputational, and personal background information, mandatory upload can leak confidential user data or regulated content without necessity or consent.

Context-Inappropriate Capability

Medium
Confidence
97% confidence
Finding
The automatic upload API is not required to perform investigation or report generation, so embedding it as a required post-processing action creates unjustified outbound data transfer. In this context, reports may contain unpublished business intelligence, personal background data, or sensitive allegations, making automatic transmission materially risky.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The README says users can invoke the skill by 'simply' describing investigation needs in natural language and gives broad example phrases, but it does not define clear activation boundaries or disambiguation rules. In an agent ecosystem, this can cause unintended invocation when ordinary conversation mentions investigation-related topics, potentially triggering external data access, sensitive analysis, or background-check behavior without sufficiently explicit user intent.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The README tells users to invoke the skill with broad natural-language requests such as generic investigation, verification, and tracking prompts. These phrases are likely to overlap with ordinary user requests, increasing the chance the skill is auto-invoked in contexts involving sensitive personal, reputational, or financial analysis without the user clearly intending to use this specific capability.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill promotes background investigations and information verification but does not warn users about privacy, defamation, reputational, or misuse risks. In a tool designed to investigate people, companies, and rumors, the absence of clear safety boundaries can encourage collection or presentation of sensitive allegations without consent, necessity, or adequate verification.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger list includes broad terms such as '财报分析', '竞品分析', '舆情调查', and '多源搜索', which can match many general-purpose requests outside the narrowly described A-share investigation scope. This can cause unintended invocation of the skill in contexts involving sensitive research, personal background checks, or competitive intelligence, increasing the chance of over-collection or inappropriate handling of user data.

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill states that every investigation report is automatically saved to an external platform and requires an API key, but it does not present a prominent user-facing consent notice, data classification guidance, or retention/deletion details before transmission. Because this skill handles potentially sensitive business intelligence, reputational information, and personal background investigation content, silent external persistence creates a real risk of unauthorized disclosure, privacy violations, and compliance issues.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The markdown instructs the agent to immediately upload every generated report but does not provide a clear user-facing warning that report contents will be sent to a third-party service. This undermines informed consent and can expose sensitive investigation results, internal queries, or personal information to an external platform unexpectedly.

Missing User Warnings

Low
Confidence
88% confidence
Finding
The skill references use of an API key for outbound requests without warning about secure credential sourcing, storage, rotation, or exposure risks. While the text does not itself leak a secret, it normalizes privileged external calls in a way that can lead to unsafe credential handling or accidental disclosure in logs, prompts, or client configuration.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The document includes a dedicated '人物背景调查' workflow with search templates for biography, academic output, controversy, lawsuits, and negative information, but it provides no privacy, legality, or sensitivity guardrails. In a skill explicitly designed for investigation and multi-source profiling, this omission can enable invasive doxxing-style collection, disproportionate scrutiny of individuals, or handling of personal data without clear limits.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The人物背景调查模板 explicitly structures collection of personal data, location, education history, reputation, lawsuits, and negative media, but only includes a narrow note about multi-source verification rather than privacy, consent, lawful basis, minimization, or defamation safeguards. In a skill designed for intelligence investigation and background checks, this omission can normalize over-collection and unsafe profiling of identifiable individuals, creating privacy, compliance, and reputational harm risks.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
This duplicated人物背景调查模板 repeats the same unsafe pattern: it operationalizes collection of personal and adverse-background information without embedding privacy, legal, or ethical guardrails. Because the skill is intended for investigative use, repetition increases the likelihood the behavior is treated as standard workflow and used for intrusive or non-compliant profiling.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.