Back to skill

Security audit

Roundtable

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly coherent, but it saves full roundtable discussions, including user context, without enough retention, deletion, or no-save controls.

Review this skill before installing if you plan to discuss personal, business, legal, financial, or confidential topics. Use explicit /roundtable commands where possible, avoid putting sensitive details into prompts, and only accept archival when you are comfortable with the full discussion being saved in memory. Ask the publisher for no-save, deletion, retention, and redaction controls before using it for sensitive decisions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (12)

Intent-Code Divergence

Low
Confidence
74% confidence
Finding
The skill promises character purity and says task/topic data should never be written back to role files, yet it also supports external character import and persistent storage without defining concrete enforcement controls in this file. That gap creates a realistic risk that imported or generated character files may retain sensitive prompt data or become contaminated with prior topics, causing privacy leakage or cross-session prompt poisoning.

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The file specifies a default behavior to archive accepted reports into `memory/`, introducing persistent data storage beyond the core discussion/orchestration function. This creates a risk of retaining sensitive user prompts, deliberation content, or decision artifacts without clear consent boundaries, retention policy, or scope limitation.

Context-Inappropriate Capability

Medium
Confidence
89% confidence
Finding
Automatic writes to persistent memory are not necessary to orchestrate a roundtable discussion and therefore expand the skill's effective authority and data-handling surface. If users discuss confidential business, personal, or strategic topics, those contents may be silently retained and later exposed to unrelated workflows or users depending on the platform's memory model.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are broad natural-language patterns such as '帮我做个决策', '从多个角度分析', and '有什么风险', which can match many ordinary conversations and invoke the skill unexpectedly. In a multi-agent orchestration skill that can load roles, run structured workflows, and persist outputs, unintended activation increases the chance of unwanted data processing, confusing behavior, and accidental archival of sensitive content.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill states that discussion records are saved to memory files but does not clearly warn users that potentially sensitive deliberation content will be persisted. Because this skill is designed for decision-making and may collect strategy, business, or personal context, silent persistence can create privacy, confidentiality, and compliance risks.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The template uses very broad domain keywords such as 'AI', 'LLM', 'Agent', and 'prompt', which can cause the roundtable system to auto-select this template for loosely related requests. In a multi-agent orchestration skill, incorrect template matching can steer users into the wrong expert set and decision flow, producing misleading analysis or bypassing more appropriate specialized templates.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The template uses broad domain keywords such as 战略, 方向, 规划, 市场, 职业, and 跳槽 that can match many normal conversations, causing the roundtable skill to activate outside clearly intended contexts. In an agentic system, over-broad routing can expose users to unintended multi-agent prompting, unnecessary retrieval/expert invocation, or decision-shaping outputs when the user did not explicitly request this skill.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The domain keyword list is broad and includes common product-discussion phrases such as “App”, “平台”, “副业”, and “要不要做”, which can cause the skill to activate in conversations that did not intend to invoke a multi-agent decision framework. In an agent system, over-broad triggering can redirect normal user requests into a more powerful workflow, increasing the chance of unwanted tool use, scope creep, or confusing outputs.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The domain keywords are broad, conversational phrases such as “评估一下”, “靠谱吗”, and “坑”, which can appear in ordinary user requests outside a deliberate risk-assessment workflow. This can cause unintended invocation of the skill, leading to context hijacking, unexpected multi-agent behavior, or inappropriate routing of sensitive discussions into this template.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs the system to archive complete discussion records plus final reports to persistent storage, but provides no consent flow, retention limits, redaction guidance, or warning that sensitive user content may be stored. In a multi-agent deliberation skill, users are likely to include strategic, personal, or confidential information, so silent persistence increases privacy and data-handling risk.

Ssd 3

Medium
Confidence
97% confidence
Finding
The task decorator explicitly includes user-provided personal information and the documentation says decorator content exists in discussion archives, which are persisted for later retrieval. Persisting personal data in reusable memory records materially raises the risk of privacy breaches, over-retention, unintended secondary use, and disclosure of sensitive user context across future sessions.

Ssd 3

Medium
Confidence
93% confidence
Finding
The preview explicitly includes '已识别的个人信息/约束', which encourages the system to extract and surface recognized personal information back into the workflow. In a multi-agent skill, this increases unnecessary collection, propagation, and possible exposure of sensitive user data across prompts, logs, or downstream agent contexts.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.