Back to skill

Security audit

AI 法律助手

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed legal-AI product guide with high-stakes content warnings, but it does not install code, run commands, persist itself, or access user data on its own.

Before installing, understand that this skill can shape legal-assistance responses and product prompts, so users should keep jurisdiction, date of law, and licensed-lawyer review in the workflow. It is appropriate as a legal-AI build guide or drafting aid, not as a substitute for professional legal advice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger description lists many broad phrases such as general legal-help, contract review, clause interpretation, and legal consultation terms, which can cause the skill to activate for a wide range of ordinary user requests. In a legal-advice context, over-broad activation is risky because it may steer users into regulated or high-stakes guidance flows without clear consent, scope checks, or jurisdiction/language qualification at the moment of invocation.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.