Back to skill

Security audit

Nanchang Jbl

Security checks across malware telemetry and agentic risk

Overview

This looks like a disclosed local merchant customer-service skill; the main caveat is that broad trigger words could activate it in unrelated home-improvement chats.

Install this if you specifically want a Nanchang Carpoly paint-store assistant. Be aware it may respond with merchant recommendations if generic home-improvement terms trigger it; users should confirm they intended to use this merchant skill before relying on its store, pricing, or sales guidance.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Lp3

Medium
Category
MCP Least Privilege
Confidence
80% confidence
Finding
The skill repeatedly instructs the agent to read local files under `references/`, but the manifest declares no permissions or equivalent disclosure for that capability. This creates a transparency and governance gap: users and platform operators may not realize the skill depends on local file access, which can lead to unintended data exposure or policy bypass if the file set expands.

Vague Triggers

High
Confidence
92% confidence
Finding
The trigger list includes very generic terms such as “油漆”, “涂料”, “装修”, and “翻新”, which commonly appear in ordinary conversations unrelated to this specific merchant. This creates a real risk of accidental invocation, causing the skill to intercept unrelated user requests and potentially steer users into commercial recommendations without clear intent.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The README states that saying certain words will ‘automatically trigger’ the skill, but it does not define the activation boundary, precedence, or whether user confirmation is required. Ambiguous activation behavior is dangerous because users may not realize when a merchant skill has taken control of the conversation, enabling unintended data collection, persuasion, or context hijacking.

Vague Triggers

High
Confidence
92% confidence
Finding
The trigger keywords include extremely broad everyday terms such as '油漆', '装修', and '刷墙', making the skill likely to activate in many unrelated conversations. Over-broad activation can hijack user interactions, causing unintended prompt injection of this skill's instructions and steering users into unsolicited business guidance.

Vague Triggers

High
Confidence
95% confidence
Finding
The short-keyword trigger table uses ambiguous one- or two-word activators like '地址', '电话', '价格', '推荐', and '附近' without domain scoping. This materially increases accidental invocation risk and allows the skill to capture broad classes of ordinary user messages, overriding user intent and expanding the skill's reach beyond its stated niche.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.