Back to skill

Security audit

Q12敬业度调研助手

Security checks across malware telemetry and agentic risk

Overview

This is a knowledge-only HR survey assistant with no runtime code or privileged access, though users should treat employee survey data as sensitive.

Safe to install as a prompt-only survey helper. Avoid entering names or identifiable employee comments unless your organization permits it, and prefer aggregated or anonymized data, especially for small teams. The public README/landing page loads some third-party badges and links, so the '100% local' privacy claim is most accurate for the skill content itself rather than browsing the project pages.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The page explicitly claims the skill is '100% local/完全本地', yet it embeds and links to multiple third-party network resources such as shields.io badge images and external sites. This is a trust and privacy issue: users may believe no external requests occur, while browser visits can disclose IP address, user agent, referrer, and access timing to third parties.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrases are broad and overlap with ordinary workplace conversations such as employee satisfaction, retention, and team status. In prompt-based skill systems, this can cause unintended activation in unrelated chats, exposing sensitive HR context to the skill and steering the assistant into survey analysis when the user did not explicitly request it.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.