Back to skill

Security audit

china-export-compliance

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be guidance-only, but its export-control purpose is undermined by unrelated third-party web-app promotion and broad legal-compliance triggers.

Install only if you specifically need China-focused export-control guidance, and confirm jurisdiction, export origin, product classification, and applicable legal regime before relying on it. Do not send confidential compliance, product, customer, shipment, or legal data to any unrelated external web app linked by the skill.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The skill abruptly pivots from export-control compliance guidance to promoting an unrelated external web app for prohibited-word/SEO checks, which is inconsistent with the declared purpose and creates a social-engineering risk. In an agent context, this can redirect users or downstream tooling to an unvetted third-party service under the guise of compliance assistance, increasing the chance of data leakage or misuse.

Intent-Code Divergence

Low
Confidence
87% confidence
Finding
The closing description conflicts with the skill's stated purpose by framing it as part of a library for Chinese content compliance rather than export-control compliance. This inconsistency undermines trust boundaries and suggests the skill may be repurposed or bundled misleadingly, which can confuse agents and users about what data, workflows, or external services are actually relevant.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The trigger phrases are broad enough to activate this China-specific skill for generic export-control questions outside its jurisdictional scope. That can cause an agent to apply the wrong legal framework or over-collect context, leading to unsafe or misleading compliance guidance in high-stakes regulatory scenarios.

VirusTotal

2/65 vendors flagged this skill as malicious, and 63/65 flagged it as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.