Back to skill

Security audit

AI 工作流优化专家

Security checks across malware telemetry and agentic risk

Overview

This is a markdown-only advisory skill for improving AI prompts and workflows, with no code execution, credential access, persistence, or hidden behavior found.

Install only if you want Chinese-language guidance on AI prompt and workflow optimization. Review any tool or workflow recommendations before applying them, and avoid sending sensitive data to external AI tools or the listed contact email unless you trust that destination.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill description is extremely broad and covers general AI assistance tasks such as prompt optimization, workflow design, troubleshooting, and tool selection. This can cause the skill to be invoked for many ordinary requests, increasing prompt-surface area and the chance that the skill overrides more appropriate task-specific behavior or introduces unsolicited guidance.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The example instruction explicitly requires Chinese output without indicating that this should depend on user preference or detected language. In practice, forcing a language can degrade usability, cause unintended behavior for non-Chinese-speaking users, and make the skill less aligned with user intent when auto-invoked.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.