臭肺·吐纳魄

Security checks across malware telemetry and agentic risk

Overview

The available evidence shows a research/learning-oriented skill with one activation-scope concern, but no hidden, destructive, credential, persistence, or exfiltration behavior.

Before installing, be aware that the skill may activate for broad research or learning requests. Install it if you are comfortable with that behavior, and give explicit instructions when you do or do not want it to perform web-style research.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The activation examples use very broad, natural-language requests like '帮我查一下最新的AI技术' and '学习一下量子计算', which can cause the skill to trigger on ordinary user prompts without clear user intent to invoke this specific capability. In an agent environment, overly permissive activation increases the chance of unintended web retrieval, research behavior, or delegation to dependent skills, which can expand attack surface and bypass user expectations.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal