Back to skill

Security audit

可以登錄家電的保固,並且歸檔,提供查詢

Security checks across malware telemetry and agentic risk

Overview

The bundled files are a skill-creation utility, but the public listing presents it as a home-appliance warranty tracker, so users could install a capability they did not expect.

Review before installing. Treat this as an AgentSkill creation and packaging helper, not a home-appliance warranty tracker. Only run its scripts in a workspace where you intend to create or package skill files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The guidance emphasizes making descriptions 'clear and comprehensive' as the trigger mechanism, but does not pair that with strict activation boundaries. In a skill whose purpose is to create or modify other skills, overly broad trigger descriptions can cause unintended activation and expand the situations in which a high-capability, file-modifying skill is selected.

Vague Triggers

Medium
Confidence
98% confidence
Finding
The example phrase 'any other document tasks' is an explicit catch-all trigger and models overly broad activation behavior. Because descriptions are stated to be the primary trigger mechanism, this pattern can generalize into accidental invocation of powerful skills outside their intended scope.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.