李录文明分析

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed investment-analysis framework with no evidence of hidden execution, credential access, data collection, or system changes.

Before installing, understand that this skill applies a specific Li Lu-inspired investment lens and may favor China-oriented, long-term civilization-progress themes. Use it for structured thinking, not as personalized financial advice, and verify any investment conclusion with independent research and your own risk constraints.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The activation description is overly broad for an investment-oriented skill, allowing it to trigger on vague prompts like long-term trend analysis or whether something is a direction of civilizational progress. That can cause the agent to apply a strong ideological investment framework in contexts where the user did not explicitly request it, leading to biased or inappropriate financial guidance.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The skill embeds a fixed country-specific investment claim ('China is the biggest opportunity') as a core principle rather than a contextualized viewpoint. In an investment-analysis skill, this can systematically bias recommendations toward one geography regardless of user goals, jurisdiction, diversification needs, or current market conditions.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The closing tagline reinforces a mandatory China-centric framing, which can prime downstream outputs even when the user did not request that perspective. Because this is an investment skill, repeated normative framing increases the chance of one-sided recommendations and reduces neutrality in financially consequential contexts.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal