要件事实证据对应

Security checks across malware telemetry and agentic risk

Overview

This is a Chinese legal evidence-mapping prompt template with no executable code, hidden access, persistence, or install-time behavior.

Install this only if you want Chinese-language legal evidence-mapping assistance. Confirm the relevant jurisdiction, statute, facts, and burden-of-proof analysis with a qualified legal professional before relying on it for court preparation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger conditions are very broad and generic, so the skill may activate for loosely related legal questions without clear user intent. In an agent environment, over-broad activation can cause incorrect tool/skill selection, leading to irrelevant legal guidance, unintended disclosure of sensitive case facts into the skill context, or overconfident evidence-mapping output when the user did not request this workflow.

Natural-Language Policy Violations

Medium
Confidence
83% confidence
Finding
The skill content is written to require Chinese output with no user-choice or locale negotiation, which can misalign with the user's language, jurisdiction, or comprehension needs. In legal contexts this is risky because misunderstandings in burden-of-proof, evidentiary categories, or litigation strategy can materially affect decisions, and forced-language behavior may also bypass higher-level system language preferences.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal