SupplyFlow — 供应链管理

Security checks across malware telemetry and agentic risk

Overview

SupplyFlow is a local supply-chain analysis toolkit with broad triggers but no hidden network, credential, persistence, or destructive behavior found.

Install this if you want a local supply-chain helper. Provide only intended inventory, supplier, purchasing, or forecasting data, and review generated purchase orders before using them operationally. Be aware that the advertised free/paid split is described in text but not enforced by the local scripts.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The general trigger list includes broad terms such as "供应链", "供应链管理", and "supply chain", which can cause the skill to activate for vague or incidental mentions rather than clear user intent. This is primarily a scope/selection security issue: unintended activation can expose the skill in contexts where its outputs are irrelevant, increasing the chance of prompt interference, confusion, or accidental processing of sensitive business data.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal