Back to skill

Security audit

deeply 证据层

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed evidence-search helper that sends judgment questions to a public external API and does not install code, persist data, or request credentials.

Before installing, understand that relevant user questions may be sent to deeply.dev for evidence retrieval. Use it for source-backed judgment questions in the stated domains, and avoid it for private, sensitive, current-news, medical, legal, or unsupported topics unless you are comfortable sharing the query with that service.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill advertises activation for very broad 'judgment' questions and even says it should be invoked when the user has not explicitly asked for expert opinions. That can cause over-triggering, unnecessary external data access, and inappropriate influence on responses in domains where the tool is stale, inapplicable, or not desired by the user.

Natural-Language Policy Violations

Medium
Confidence
83% confidence
Finding
The instruction to '尽量用中文说明' biases output language regardless of the user's requested language or conversation context. This can degrade reliability, violate user expectations, and create prompt-level conflicts where the tool steers the assistant away from following user preferences.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.