Back to skill

Security audit

Enterprise Business Information Inquiry - 企业工商信息查询

Security checks across malware telemetry and agentic risk

Overview

This is a read-only company information lookup skill that uses the disclosed JisuAPI service and does not show hidden, destructive, or persistent behavior.

Install if you are comfortable using a JisuAPI AppKey and sharing searched company names or registration identifiers with JisuAPI. Use a dedicated, quota-limited key when possible, and avoid submitting confidential research targets unless that third-party disclosure is acceptable.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
85% confidence
Finding
The invocation description uses broad language like '或类似工商信息问题时,使用本技能', which can cause the agent to invoke the skill for loosely related requests without clear user intent. In a skill that sends company identifiers to an external provider, overbroad triggering increases the chance of unnecessary data disclosure to a third party and unexpected external calls.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The markdown instructs sending company names and identifiers to JisuAPI but does not warn users that their query data will be transmitted to a third-party service. This creates a privacy and transparency risk, especially when identifiers such as unified social credit codes or registration numbers may be sensitive in enterprise workflows.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.