Back to skill

Security audit

聊天助手

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed chat-relationship advice helper that asks users to provide relationship context and chat logs, with no evidence of hidden execution, exfiltration, or destructive behavior.

Install this only if you are comfortable pasting private chat records and relationship details into the assistant. For best privacy, provide only the conversation snippets needed for advice and avoid unnecessary identifying details.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The activation description is broad enough to trigger on ordinary requests about replying to messages or discussing relationship context, which can cause the skill to activate without clear user intent to use persistent relationship analysis. Because the skill is designed to collect and organize sensitive interpersonal chat histories by named contacts, overbroad activation increases the chance of unnecessary ingestion of private data and context confusion.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The intent-recognition logic includes vague triggers like '帮我回' and '怎么回' without requiring confirmation that the user wants this specialized skill or that a specific contact context is intended. In a system with multiple skills, such ambiguity can cause incorrect routing and unintended processing of sensitive communications, especially since this skill maintains separate relationship dossiers and automatic analysis flows.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.