Back to skill

Security audit

中国3C营销助手

Security checks across malware telemetry and agentic risk

Overview

This is a coherent China 3C marketing assistant, with reasonable cautions around broad automatic routing and local data-import file updates.

Install this if you want a Chinese-language assistant for China 3C marketing strategy and material review. Keep it scoped to marketing work, verify high-timeliness facts before relying on them, and review diffs before allowing data-import workflows to update knowledge-base indexes or SKILL.md. Do not treat its go/no-go recommendations as a substitute for legal, advertising-compliance, product-safety, or brand approval.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (15)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill enables implicit invocation with no trigger phrases, scoping rules, or user-confirmation guardrails. That means the assistant may automatically route loosely related conversations into this marketing skill, increasing the chance of unintended activation, context leakage into the skill, or off-scope persuasive/business advice being produced without the user explicitly opting in.

Vague Triggers

Medium
Confidence
93% confidence
Finding
触发条件使用“处理新数据”“我导入了新文件”这类日常短语,缺少确认步骤、上下文约束或明确命令前缀,容易在正常对话中误激活子智能体。该技能会进一步处理文件并生成/更新知识库内容,误触发可能导致非预期的数据摄取、结果污染或后续文件修改。

Vague Triggers

Medium
Confidence
95% confidence
Finding
“工作目录中出现新的原始数据文件”作为自动激活条件边界过宽,未限定监控目录、允许的文件来源、命名规则或人工确认,任何新文件都可能触发处理流程。在具备写文件能力的代理环境中,这会放大被投喂恶意/无关文件、自动处理敏感内容或连锁修改仓库内容的风险。

Missing User Warnings

Low
Confidence
88% confidence
Finding
文档要求“更新品类 _index.md 和 SKILL.md 主入口中的相关索引”,但未明确提示这是对仓库文件的持久化修改,也未要求确认或说明修改范围。用户可能只期望数据处理,却实际触发额外写操作,带来内容污染、误提交或覆盖人工维护索引的风险。

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger conditions include very common phrases like '帮我检查', '审核', and '这个靠谱吗', which can appear in ordinary conversation and are not tightly scoped to fact-checking for formal marketing materials. This can cause the subagent to activate unexpectedly, override the intended workflow, or inject adversarial/audit-style behavior into benign requests, creating reliability and policy-boundary problems.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The document is written to produce a fixed Chinese-language output format without any instruction to respect the user's language preference. While not directly a security exploit, forced language can degrade transparency, cause users to miss warnings or compliance issues, and create unsafe misunderstandings in multilingual workflows.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger definition is broad and based on a long list of common marketing asks without explicit exclusion criteria or tighter scope checks. In an agent setting, this can cause the skill to activate on loosely related requests and steer outputs into campaign-generation workflows even when the user intent is ambiguous, increasing the chance of inappropriate automation, missed safeguards, or irrelevant persuasive content.

Missing User Warnings

Low
Confidence
78% confidence
Finding
The route specifies a hidden '后台读取' execution-readiness gate for formal launch or paid distribution, but does not surface to the user that internal compliance, legal, risk, and pause-condition checks are being applied. This reduces transparency and can create misleading expectations about how outputs are produced or approved, especially in regulated or reputation-sensitive campaign contexts.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger is broad enough that many loosely related inputs such as comments, specs, competitor materials, or a generic request to 'process new data' can invoke this route unintentionally. In a skill that performs data import, file handling, and downstream script execution, over-broad activation increases the chance of misrouting sensitive or irrelevant user content into analysis and storage workflows.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger scope is broad enough to activate on loosely related requests such as budget tradeoffs, management reporting, or generic execution advice, which can cause the agent to enter a high-authority launch-decision workflow without clear boundaries. In a marketing strategy skill, this increases the chance of over-collection, misrouting, and users receiving operational recommendations beyond what they explicitly asked for.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The trigger criteria are broad and overlap with many generic copywriting, slogan, and messaging requests, which can cause the route to activate outside its intended scope. In an agent skill, overbroad routing can expose users to specialized policy, risk, or execution logic when they asked for ordinary writing help, increasing the chance of misclassification, unintended data flow across documents, and confusing or unsafe outputs.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger language is broad enough to activate on generic requests like scoring, review, or deliverability checks, which can cause the skill to engage outside its intended narrow domain. In an agent setting, overbroad routing can lead to inappropriate instruction loading, context switching, and application of domain-specific policies to unrelated user tasks, reducing reliability and potentially bypassing safer or more appropriate routes.

Natural-Language Policy Violations

Medium
Confidence
80% confidence
Finding
Requiring a fixed '中国3C表达' style dimension without user opt-in can force locale-specific framing onto outputs even when the user's request does not ask for it. This is primarily a scope and policy-alignment issue: it can produce mismatched or biased output, and when combined with broad routing, it increases the chance of inappropriate behavior on out-of-scope tasks.

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
This template is entirely in Chinese and does not disclose a locale restriction or offer a language fallback, which can cause non-Chinese-speaking users or downstream reviewers to misunderstand execution gates, risk thresholds, and stop conditions. In a decision-support skill that determines go/no-go, hidden language assumptions increase the chance of unsafe or incorrect execution because critical checks may be skipped or misapplied.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger conditions are broad enough to match vague, everyday requests such as '帮我做传播' or '这个怎么打', which can cause the skill to activate without a sufficiently specific marketing context. In this skill, unintended invocation is meaningful because outputs can influence external messaging, budget, channel, and KOL decisions, so misfiring on underspecified prompts could produce inappropriate strategic guidance or bypass safer routing to general-purpose assistance.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.