Back to skill

Security audit

周末去哪玩|只推一个

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed weekend outing recommendation helper with bounded public-search, memory, and packaging behavior; the scanner concerns are mostly usability or release-workflow notes rather than security issues.

Install if you want a Chinese-language helper for deciding one weekend outing. Expect it to use public search or browser access when available, but it should not log in, bypass restrictions, scrape in bulk, download media, or save preferences unless you explicitly choose to remember them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding
The skill is presented as a simple outing recommendation tool, but the embedded instructions also describe repository validation, packaging, file inspection, and live-browser evidence checks that are unrelated to the user-facing purpose. This hidden operational scope can cause an agent to read/write files or perform broader actions than a user would reasonably expect, increasing the risk of over-privileged execution and unintended data or system access.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The activation rule '用户给 3-5 个地点名或链接时,直接进入候选裁决模式' is broad enough to trigger on casual mention of places or pasted links without confirming the user actually wants a single recommendation. In an agent setting, over-broad activation can cause the wrong skill to take control, leading to irrelevant guidance, missed user intent, and unsafe or low-quality recommendations if key constraints were never gathered.

Natural-Language Policy Violations

Medium
Confidence
82% confidence
Finding
The file is written to enforce Chinese-language interaction and output structure without indicating that language should follow user preference. This can cause accessibility and usability failures, especially if the broader system serves multilingual users, and may lead to misunderstanding of safety, budget, transport, or risk details.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.