法条决策树生成

Security checks across malware telemetry and agentic risk

Overview

This is a Chinese-language legal workflow helper that formats prior statute analysis into a decision tree and does not include code execution or hidden data access.

Install this only if you want a Chinese-language legal decision-tree drafting aid. Treat generated outputs as drafting support rather than legal advice, and avoid entering confidential case details unless the surrounding agent environment is trusted.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are broad enough to match ordinary user requests such as asking to 'make an SOP' or 'generate a reusable guide', which can cause the skill to activate unintentionally. In an agent setting, over-broad activation can route users into legal-analysis behavior without clear intent, increasing the chance of misapplication, context confusion, or unauthorized handling of sensitive legal content.

Natural-Language Policy Violations

Medium
Confidence
83% confidence
Finding
The skill content is written to require Chinese-language interaction throughout without offering an alternative language path or making the constraint explicit to users. This can lead to misunderstanding of legal instructions, incorrect evidence handling, or user exclusion when the operator expects another language, especially in a legal workflow where precision matters.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal