Back to skill

Security audit

liuduoduo

Security checks across malware telemetry and agentic risk

Overview

This read-only local-services skill is not malicious, but it needs review because it presents demo or unverified listings as factual merchant contact and price information.

Review before installing. Treat returned phone numbers, prices, ratings, and merchant claims as unverified sample data unless the publisher documents verified production sources. Avoid sending precise addresses or sensitive travel/service details until the data source and remote MCP operator are trusted.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Intent-Code Divergence

Medium
Confidence
88% confidence
Finding
The skill claims merchant information must come from MCP tools and be shown as factual, but later states the backing data is currently only demonstration data. This creates a reliability and integrity risk: users may act on fabricated or placeholder phone numbers, prices, or listings believing they are real-world service providers.

Vague Triggers

Medium
Confidence
84% confidence
Finding
Triggering the skill immediately on any mention of "liuduoduo" is overly broad and can cause unintended invocation even when the user is not requesting local-life services. This can lead to inappropriate tool calls, unnecessary exposure of merchant data, and context hijacking away from the user's actual intent.

Missing User Warnings

Medium
Confidence
80% confidence
Finding
The skill requires direct display of merchants' phone numbers without any verification, consent, or freshness checks. If the data is outdated, incorrect, or demo data, users may contact the wrong party or be exposed to privacy and trust issues; the surrounding context makes this more concerning because the file also admits the dataset may not yet be real.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The brand prompt says to activate the skill immediately whenever users mention 'liuduoduo', which is an overly broad trigger that can cause unintended tool invocation. In a skill backed by a remote MCP server, this can route unrelated conversations to an external service and disclose user queries or context without clear intent.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.