快递查询

Security checks across malware telemetry and agentic risk

Overview

This skill provides courier hotline lookup and delivery-issue guidance using static local data, with no hidden access, persistence, or destructive behavior found.

Reasonable to install for Chinese courier contact lookup and delivery-problem guidance. Treat phone numbers, service hours, complaint portals, and compensation rules as time-sensitive and verify important details through official carrier channels before acting.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill enables implicit invocation without any trigger constraints, so the agent may route unrelated user requests into this skill based only on broad semantic similarity. Because the skill is designed to provide operational guidance around courier complaints, contact channels, and scam-related issues, over-broad auto-invocation can cause unintended disclosure, misrouting, or low-trust advice being surfaced when the user did not explicitly ask for it.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal