Back to skill

Security audit

投标文件智能编写

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed client for uploading user-provided bid documents to the 招采猫 API to generate and review tender materials, with expected credential storage and output files.

Install only if you are comfortable uploading tender and bid documents, which may contain commercial or personal information, to 招采猫 cloud processing under your App Key. The generated files and task results are described as retained on that service for about 7 days, and bid generation may consume account credits. Keep the App Key private, prefer manual credential-file setup if you do not want it in chat history, and do not change the API base URL unless you trust the destination.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.