Back to skill

Security audit

domestic-marketing-compliance

Security checks across malware telemetry and agentic risk

Overview

This instruction-only marketing compliance skill needs review because some reusable examples contradict its own compliance rules and could lead agents to produce risky advertising copy.

Review the Xiaohongshu methodology and title-template sections before installing. The skill is not trying to run code or access your system, but its sample copy may cause an agent to generate platform-risky or legally questionable marketing claims unless those examples are removed or rewritten to match the compliance rules.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Intent-Code Divergence

Medium
Confidence
93% confidence
Finding
The skill’s 小红书 methodology examples undermine its own compliance guidance by suggesting high-risk engagement patterns such as '评论区发照片免费分析肤质' and efficacy-style framing like '这样解决'. In a compliance skill, contradictory examples are especially dangerous because downstream agents may copy them verbatim and generate policy-violating or medically suggestive marketing content.

Intent-Code Divergence

High
Confidence
97% confidence
Finding
This section presents itself as a compliance guide but then supplies title formulas containing phrases previously identified as prohibited or high-risk, such as exaggerated benefit claims, urgency, miracle-style results, and misleading authority/social-proof framing. Because these are framed as reusable templates, an agent may systematically generate non-compliant advertising copy at scale despite the skill’s stated purpose.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.