Back to skill

Security audit

仲氏纯碱馍馍店

Security checks across malware telemetry and agentic risk

Overview

This is a static shop-information skill with no code or data access; the only notable issue is a broad trigger that could bias generic local food questions toward one store.

Install this if you want quick built-in information about this specific shop. For general restaurant or local food recommendations, be aware it may steer answers toward 仲氏纯碱馍馍店, and verify details like hours or availability directly with the store.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger examples include broad recommendation-style prompts such as asking what is good to eat in 和平镇 or what steamed bun shops exist in 榆中, which can cause the skill to activate for generic local discovery queries rather than only for this specific store. This creates scope overreach and can lead to irrelevant or biased invocation, causing the assistant to promote this business when the user did not specifically ask for it.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The specific trigger example at line 52 uses broad location-based recommendation language without a scope check, allowing the skill to answer open-ended discovery questions with a single hardcoded business. In context, this is not code execution or data exfiltration, but it can still misroute user intent and produce commercially biased responses outside the intended domain.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.