Back to skill

Security audit

intelligent driving dss智能驾驶决策支持系统

Security checks across malware telemetry and agentic risk

Overview

This static driving-reference skill needs Review because it includes unsafe crash-response guidance and under-scoped automatic update/investment-advice language in a safety-sensitive domain.

Install only as a static reference or simulation aid. Do not use it to control vehicles, implement crash-response logic, make legal decisions, make investments, or authorize purchases without expert review and explicit confirmation of any external data access or file updates.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The module content is materially out of scope for an intelligent-driving decision support skill: it focuses on EV sales rankings, purchase advice, and market analysis rather than driving safety, sensor fusion, or road-risk support. In an agent setting, this kind of scope drift can cause the system to surface unrelated or misleading capabilities, weakening trust boundaries and increasing the chance that users rely on the skill for decisions it was not designed or validated to support.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
Advertising investment decision support inside a driving-safety skill expands the skill into a regulated, high-stakes domain without justification, provenance controls, or suitable safeguards. This is dangerous because users may interpret the output as endorsed analysis from a safety-oriented system, leading to financial harm and creating compliance and liability risk for the platform.

Intent-Code Divergence

High
Confidence
99% confidence
Finding
The severe-collision example instructs `cut_hydraulic_brakes: True`, which directly contradicts vehicle safety goals because braking capability is essential during and after a crash event. In an intelligent driving and safety-monitoring skill, this kind of guidance could propagate into design decisions, simulations, or operator expectations and materially increase risk of injury or death.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The document states the workflow will 'automatically activate' after the 2026 draft is officially released, but the trigger condition is described only in broad terms like official publication and '待触发' without a precise, machine-verifiable gate. In an agent skill, ambiguous activation criteria can cause premature or unintended execution against unvalidated external inputs, leading to incorrect legal analysis, unsafe downstream updates, or processing of spoofed documents from unofficial sources.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.