Back to skill

Security audit

问题总结

Security checks across malware telemetry and agentic risk

Overview

This is a simple formatting skill that creates a copyable Chinese problem summary and does not execute code or send data anywhere by itself.

Install only if you want Chinese copy-ready summaries for sharing with other AI tools. Review and redact personal, confidential, or proprietary details before pasting the generated summary into an external platform, and be aware that broad summary-like requests may trigger it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
85% confidence
Finding
The trigger examples are broad natural-language phrases like '总结一下问题' and '整理一下去问豆包', which can plausibly appear in ordinary conversation without the user intending to invoke a skill. This can cause unintended activation, leading the agent to summarize conversation content for export to another platform and potentially disclose more context than the user meant to share.

Natural-Language Policy Violations

Medium
Confidence
82% confidence
Finding
The README states the skill activates on Chinese-language phrases and outputs a Chinese three-part summary, without indicating any check for the user's language preference. This can override user expectations and produce output in an unintended language, which is a safety and usability issue and may increase the chance of miscommunication when sharing technical problem details elsewhere.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger conditions are broad and include catch-all phrasing such as '其他类似表达', which can cause the skill to activate on loosely related requests. In an agent environment, unintended activation can override the user's expected workflow, produce unsolicited reformulations, and route sensitive conversation content into a copyable summary without clear user intent.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.