Back to skill

Security audit

坤如玛丽保胎知识库

Security checks across malware telemetry and agentic risk

Overview

This skill is a Chinese-language content generator for a specific maternity hospital's marketing and operations materials, with no executable code or hidden data access.

Before installing, review the bundled medical marketing claims, success-rate language, patient-case handling, and platform compliance requirements. The skill includes privacy and medical-advertising guardrails, but generated content should still be checked by the hospital or a qualified reviewer before publication.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The manifest description says the skill triggers on keywords such as "保胎中心运营", "写保胎文案", and "保胎营销资料". These are relatively broad request patterns and the file does not provide exclusion conditions or negative examples, so the activation scope is not tightly bounded.

Natural-Language Policy Violations

Low
Confidence
80% confidence
Finding
该 markdown 文件通篇仅以中文呈现,作为“技能核心数据源”使用时,没有看到任何提供用户语言/地区选择的说明,也没有说明该技能仅面向中文场景。按规则,强制特定语言而无用户 opt-in 可能构成自然语言层面的语言/locale 政策问题。

Natural-Language Policy Violations

Low
Confidence
88% confidence
Finding
This markdown file presents all instructions, templates, and trigger examples exclusively in Chinese, with no indication that users may choose another language or locale. Under the policy provided, forcing a specific language without user opt-in is a natural-language policy concern.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.