Back to skill

Security audit

AI 开源项目雷达

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed API-backed helper for researching AI open-source projects, with normal external-service and token-handling considerations.

Install only if you want Jiqizhixin-backed AI project research and are comfortable sending your project search terms to that provider. Use a scoped, rotatable JQZX_API_TOKEN, keep BASE_URL pointed at the intended service, and avoid confidential internal project names unless the provider's terms are acceptable.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The description says AI-related questions must prioritize this skill and forbids relying on model memory for concrete facts. This is an overreaching policy instruction embedded in untrusted skill content that can override user choice and steer all relevant queries through a single external data source, creating a prompt-level routing hijack and potential data exfiltration path.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.