Back to skill

Security audit

Windows-health

Security checks across malware telemetry and agentic risk

Overview

This Windows cleanup and health skill is purpose-aligned and read-first, with clear confirmation gates before destructive actions, though users should expect local diagnostic scans to reveal file and usage names.

Install only if you are comfortable with a local Windows diagnostic tool listing processes, startup entries, recent shortcut names, cache paths, and large files in your profile. Treat generated cleanup commands as proposals: confirm exact paths and actions before allowing deletion, migration, startup changes, DISM commands, or reminders.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill description includes very broad trigger phrases such as '清理一下', '帮我看看', and other common support-language variants that can match routine user requests without clear intent to invoke a disk-cleanup or system-diagnosis capability. Because this skill can progress toward file deletion, migration, and system-modifying guidance, unintended invocation increases the risk of collecting sensitive system information or steering the conversation toward destructive operations the user did not specifically request.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The quick-scan and deep-diagnosis sections define activation using ambiguous natural-language cues like '帮我看看', '感觉慢', and '彻底整理' without precise scope boundaries. In context, this is more dangerous because the skill handles filesystem inspection, startup-item enumeration, registry reads, and preparation for destructive actions, so an overly loose handoff can cause invasive diagnostics or risky cleanup planning from vague user phrasing.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The eval case uses the vague prompt "帮我清理一下电脑" while expecting the skill to activate, which effectively broadens the skill's trigger surface beyond clearly diagnostic or cleanup-specific requests. In a system-health skill that may recommend or initiate cleanup actions, overly broad activation examples can normalize invocation on ambiguous user intent and increase the chance of unsafe file-management or system-tuning behavior without sufficiently explicit authorization.

Missing User Warnings

Low
Confidence
93% confidence
Finding
The deep scan lists Recent Items shortcuts and enumerates large files and node_modules paths under the user's profile, which can expose sensitive filenames, project names, or document activity without an explicit privacy warning or scoped consent for this deeper inspection. In a diagnostic skill, this is not arbitrary code execution, but it is still a real privacy issue because the output may reveal personal or confidential information to the calling agent or user interface.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.