Back to skill

Security audit

飞书产品需求交付

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed workflow for turning product-page research into a confirmed Feishu requirements document, with explicit confirmation and privacy gates before publication.

Before installing, be aware that this skill may use your signed-in browser session to inspect related product pages, capture screenshots, and create or update a Feishu document. Use it only on pages and destinations you intend to share, and review the confirmed baseline before allowing publication.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The default prompt activates the skill for a broad class of requests without clear guardrails on scope, permissions, or required user confirmation before investigating pages and publishing to Feishu. In a skill that accesses signed-in pages and produces externally published documentation, ambiguous triggering can cause unintended data access, over-collection, or publication actions when the user intent was narrower.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.