Security audit
投标文件智能编写
Security checks across malware telemetry and agentic risk
Overview
This skill is a disclosed client for uploading user-provided bid documents to the 招采猫 API to generate and review tender materials, with expected credential storage and output files.
Install only if you are comfortable uploading tender and bid documents, which may contain commercial or personal information, to 招采猫 cloud processing under your App Key. The generated files and task results are described as retained on that service for about 7 days, and bid generation may consume account credits. Keep the App Key private, prefer manual credential-file setup if you do not want it in chat history, and do not change the API base URL unless you trust the destination.
SkillSpector
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
65/65 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
