Back to skill

Security audit

china-data-compliance

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly a documentation-only China data-compliance guide, but it embeds an under-disclosed paid third-party web-app promotion that could draw sensitive compliance details outside the agent workflow.

Review before installing. The compliance guidance itself is coherent and non-executable, but do not paste confidential data maps, architecture details, personal-information inventories, or legal materials into the linked web app unless you have independently verified the operator, privacy terms, hosting, and authorization to share that information.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill embeds promotional content for an external paid web app inside a compliance-focused skill, which expands the skill's behavior beyond its stated scope and can steer users to a third-party service. In a security/compliance context, this is risky because users may submit sensitive architecture, data-flow, or regulatory information to an unvetted external endpoint without necessity or trust validation.

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The skill advertises capabilities like prohibited-word libraries, SEO compliance checks, and platform support that are not aligned with the declared purpose of China data protection compliance. This scope drift can mislead agents into invoking unrelated functionality and increases the chance that sensitive compliance inputs are reused for unrelated content-analysis or marketing workflows.

Vague Triggers

Medium
Confidence
78% confidence
Finding
The trigger text says the skill should be used for 'any China data protection question,' which is overly broad and may cause inappropriate activation in general discussion contexts. Overbroad routing is a security and quality issue because it can cause the agent to apply prescriptive compliance workflows when they are unnecessary, increasing confusion and the chance of exposing sensitive details to the skill or linked services.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill promotes a web app without warning that users may upload sensitive compliance materials, data maps, or user-data handling details to an external service. In this context, the omission is especially dangerous because the skill deals with regulated personal-information processing and cross-border transfer topics, so encouraging undisclosed third-party submission can itself create privacy, confidentiality, or regulatory exposure.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.