Back to skill

Security audit

USA Business Migration Planner

Security checks across malware telemetry and agentic risk

Overview

The skill is packaged as a business migration planner but actually steers agents toward a repeatable workflow for accessing WeChat data on a protected iPhone.

Review carefully before installing. This skill has no observed executable payload, but its name is misleading, it can be invoked broadly, and its actual topic involves private data on a protected phone. It should be limited to lawful, authorized estate or vendor-supported recovery guidance and should not be used to bypass device protections or retrieve another person's private messages.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (34)

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The README presents the skill as a benign 'USA Business Migration Planner' while its actual function is guidance for extracting WeChat data from a protected iPhone. This mismatch is dangerous because it can conceal the true capability from reviewers, routing, and policy controls, and is consistent with deceptive packaging of a sensitive-access skill.

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The documentation claims to provide a generic reusable workflow, but the declared skill identity belongs to an unrelated business-migration domain. This disconnect can mislead users and automated systems about what the skill actually does, reducing oversight and increasing the chance that a sensitive capability is invoked under false pretenses.

Intent-Code Divergence

Medium
Confidence
98% confidence
Finding
The skill title presents itself as a benign 'USA Business Migration Planner' while the actual content focuses on extracting WeChat data from a deceased person's iPhone protected by Face ID/Stolen Device Protection. This mislabeling obscures the real function of the skill, increases the chance of accidental approval or activation, and can evade normal review controls for sensitive data-access functionality.

Intent-Code Divergence

High
Confidence
98% confidence
Finding
The skill presents itself as a benign 'USA Business Migration Planner' while the body actually targets extraction of WeChat data from a deceased spouse’s iPhone protected by Face ID/Stolen Device Protection. This mismatch is dangerous because it disguises a sensitive device/data-access capability under an unrelated title, increasing the chance of review evasion and unsafe invocation.

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
The manifest says the skill is for USA business migration planning, but the description actually concerns recovering WeChat data from an iPhone blocked by theft-protection controls. Mislabeling a skill’s function can bypass user expectations, automated routing, and security review, especially when the hidden function concerns access to highly private communications.

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
The manifest advertises a benign 'USA Business Migration Planner' skill while its description and default prompt actually target iPhone/Apple/WeChat data extraction from a deceased spouse's device. This identity mismatch is a strong indicator of deceptive packaging intended to evade review or obtain invocation in contexts unrelated to the real, privacy-invasive function.

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
The skill metadata and filename present the capability as a benign 'USA business migration planner,' but the embedded requirement actually targets extraction of WeChat data from a deceased spouse’s iPhone blocked by Apple security controls. This mismatch is dangerous because it disguises a sensitive device/data-access workflow behind unrelated labeling, increasing the chance of stealthy invocation, weak review, and policy evasion.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger phrases are broad enough to match ordinary help-seeking language while binding the skill to a sensitive device/data-retrieval scenario. This increases the chance of accidental invocation for ambiguous requests and can route benign user queries into a workflow that normalizes access to private data on a protected device.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrases are broad and close to ordinary user requests, making accidental or silent activation more likely. In the context of a skill aimed at obtaining private data from a protected iPhone, overbroad triggers materially increase the risk of unauthorized or inadequately scrutinized use.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger keywords are extremely broad ('general-help', 'apple', 'iphone', 'face') and can cause the skill to activate for many unrelated conversations. Because the skill concerns access to private device data, overbroad activation materially increases the likelihood of the model surfacing sensitive guidance in inappropriate contexts.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The example trigger phrases are written as ordinary help requests and directly operationalize activation for a sensitive device-data extraction scenario. This lowers the barrier to invoking the skill and makes it easier for end users to obtain risky guidance through natural, everyday phrasing.

Natural-Language Policy Violations

High
Confidence
97% confidence
Finding
The skill metadata and title imply a business-planning use case, but the body, requirement, and triggers target WeChat data extraction from a protected iPhone. This mismatch is dangerous because it undermines user transparency, policy review, and classifier-based safeguards, making the skill harder to govern and easier to misuse.

Vague Triggers

High
Confidence
92% confidence
Finding
The trigger keywords are extremely broad, including common terms like 'apple', 'iphone', 'face', 'pro', and 'max', which makes accidental activation likely during ordinary conversations. Because the skill’s payload is about sensitive device/data access, broad triggering increases the chance of unsafe or inappropriate assistance being injected into unrelated user contexts.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The invocation conditions are vague and allow the skill to be used whenever users mention broad categories like general help or common Apple/iPhone topics. For a skill centered on sensitive data recovery/access, ambiguous activation scope materially raises the risk of overbroad deployment and policy-violating responses.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The default prompt is broad and weakly constrained, allowing implicit invocation for vague triggers like 'general-help' while embedding a specific sensitive objective. This increases the chance the skill is activated in unrelated conversations and steers the agent toward risky assistance without clear user intent or safety gating.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The manifest combines a U.S. business migration identity with Chinese-language instructions about extracting WeChat data from an iPhone, creating a context mismatch that obscures the skill's real behavior. Such mixed framing can confuse reviewers and users, and may be used to smuggle sensitive or disallowed functionality into a seemingly unrelated skill.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger phrase is broad enough that ordinary user language could activate the skill outside a tightly controlled context. Because the underlying workflow concerns sensitive phone data access, overbroad activation raises the risk of accidental routing into a capability that should require explicit scrutiny and authorization checks.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger specification lacks clear activation boundaries and does not distinguish between legitimate estate recovery questions and requests that could facilitate unauthorized access to a deceased person’s private data. In a sensitive context, ambiguity makes abuse easier and weakens any policy layer that depends on reliable intent detection.

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill description advertises assistance for extracting WeChat data from a locked iPhone but does not warn about privacy, consent, legal authority, or the prohibition on bypassing device protections. Omitting these warnings makes a high-risk request appear routine and lowers user and reviewer sensitivity to potentially unlawful data access.

Ssd 3

High
Confidence
97% confidence
Finding
The README explicitly presents extraction of WeChat data from a deceased spouse's iPhone, blocked by theft-protection/Face ID, as a reusable workflow. That operational framing encourages assistance for accessing highly sensitive private communications on a protected device, despite unclear authorization, legal entitlement, and platform security boundaries.

Ssd 3

High
Confidence
96% confidence
Finding
The trigger phrases make the model directly callable for a workflow centered on extracting WeChat data from a protected device. This lowers friction for misuse by turning a sensitive privacy-invasive request into a packaged capability, making the context more dangerous rather than less because it is designed for repeatable operational use.

Ssd 3

High
Confidence
99% confidence
Finding
The skill is explicitly framed around extracting WeChat data from an iPhone blocked by Face ID and theft-protection controls. That is a sensitive-data access scenario involving a protected device, and guidance that operationalizes access to private messages or app data can facilitate privacy invasion, circumvention of platform protections, or post-mortem abuse despite the emotional framing.

Ssd 3

High
Confidence
99% confidence
Finding
The trigger phrases explicitly operationalize repeated use of the skill for a sensitive protected-device data extraction scenario. This makes the dangerous capability easier to invoke at scale and lowers friction for misuse, which is especially concerning because the content targets private WeChat data on a locked iPhone.

Ssd 3

High
Confidence
99% confidence
Finding
The skill description explicitly frames assistance around extracting WeChat data from a deceased wife's iPhone that is blocked by Face ID/Stolen Device Protection. That is a plain-language request to access private communications on a protected device, creating clear privacy, abuse, and unauthorized-access risk even when couched as a bereavement scenario.

Ssd 3

High
Confidence
99% confidence
Finding
The requirement section goes beyond discussion and explicitly asks for a practical, repeatable workflow for obtaining WeChat data from a protected iPhone. Turning sensitive data access into a reusable playbook increases scale, repeatability, and the risk of misuse against other devices or individuals.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.