Back to skill

Security audit

Baidu Top - 百度热搜榜单

Security checks across malware telemetry and agentic risk

Overview

This skill fetches public Baidu ranking pages and prints the results, with only minor documentation-scope issues.

Install this if you want an agent to fetch Baidu ranking pages on request. Be aware it makes live requests to Baidu and may need Python packages installed; ignore the unrelated JisuAPI promotional section unless you separately choose to use that service.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
78% confidence
Finding
The trigger phrase '或类似百度榜单问题时' is overly broad and lacks boundaries, so the skill may activate for loosely related requests the user did not intend for this tool. In an agent environment, overbroad routing can cause unnecessary network access, wrong-tool invocation, and confusion about why an external site was queried.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.