Back to skill

Security audit

Daily Intel Report

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed daily news and procurement digest skill, with purpose-aligned web fetching, optional delivery, and no evidence of hidden data access or destructive behavior.

Install this only if you want a Chinese daily intelligence digest that fetches public web sources and may send reports to Feishu or email. Before enabling cron delivery, confirm the schedule, recipient, and SMTP or Feishu configuration, and treat fetched web content as untrusted source material.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Lp3

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding
The skill explicitly instructs use of network-capable actions such as web_fetch and execution of a scraping script, but the metadata does not declare corresponding permissions. That mismatch can bypass user/operator expectations and weaken policy enforcement, especially for a scheduled skill that continuously accesses external sites and pushes results onward.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The trigger list includes broad terms like '早报', 'AI新闻', and '招标信息', which are common phrases that may appear in ordinary conversation. This increases the chance of unintended invocation, causing unsolicited web requests, scraping, and message delivery actions without sufficiently specific user intent.

Natural-Language Policy Violations

Medium
Confidence
80% confidence
Finding
The description frames the skill as automatically producing Chinese reports and pushing them to Feishu/email without indicating user choice, consent, or configurable delivery behavior. In context, this is more risky because the skill supports scheduled execution and outbound communication, so users may receive unexpected messages or content in a forced format/channel.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.