Back to skill

Security audit

China Travel

Security checks across malware telemetry and agentic risk

Overview

This is a markdown-only China travel guide; it has some travel-safety caveats users should verify, but it does not execute code, request credentials, or add hidden access.

Installers can treat this as a travel planning reference, not an official authority. Before relying on visa, transit, hotel, payment, VPN, or late-night safety advice, verify with official sources and use official payment apps and reputable connectivity options.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Natural-Language Policy Violations

Medium
Confidence
86% confidence
Finding
The skill appears to prescribe a fixed response format and, per the finding, mandates Chinese output without checking the user's preferred language. For a travel-assistance skill serving foreign visitors, this can cause misunderstandings about visas, transit rules, payments, or emergency procedures, creating a real safety and usability risk even if it is not a classic code-execution issue.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The checklist explicitly tells travelers to prepare, install, and test a VPN, but provides no warning that VPN legality, licensing, or permitted use varies by jurisdiction and may create compliance or operational risk for users. In a travel-assistance skill, this can normalize bypass-oriented behavior and expose users to legal issues, account compromise from untrusted VPN providers, or false confidence about connectivity and privacy.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The checklist instructs users to register Alipay/WeChat Pay and bind foreign bank cards, but omits basic safety guidance for handling sensitive financial data such as using official apps, avoiding phishing links, securing devices, and understanding data-sharing implications. In a travel skill aimed at foreign visitors, this increases the chance of users exposing card data or performing onboarding over insecure networks or fake apps.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The content recommends '凌晨3点独自 city walk' as a travel challenge and frames it positively, which can normalize risky solo late-night behavior without any safety caveat. In a travel-assistance skill, users may treat such guidance as endorsed advice, increasing the chance of harm such as crime exposure, disorientation, or reduced access to help during an incident.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.