活动策划专家

Security checks across malware telemetry and agentic risk

Overview

This is a plain event-planning skill with broad trigger wording but no executable code, hidden behavior, persistence, credential use, or data exfiltration.

Installers should know this skill may activate for broad Chinese planning phrases like requests for a方案 or活动. Use it when you want event-planning help, and avoid sharing private details beyond what is needed for the plan.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill metadata advertises very broad natural-language triggers such as “帮我策划X / 做个X方案 / 办个X活动”, which overlap heavily with ordinary conversation. In an agent environment, this can cause unintended invocation on benign user requests, routing sensitive or unrelated conversations into this skill without clear user intent.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The scene-recognition table uses many high-frequency generic keywords like “活动”, “会议”, “培训”, “旅游”, and “开业”, with little disambiguation logic. This increases the chance that routine discussion containing these words will incorrectly activate the skill or classify the wrong scenario, leading to unintended data collection and incorrect workflow execution.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal