双色球选号系统 v2
Security checks across malware telemetry and agentic risk
Overview
This skill is a disclosed lottery-number helper that runs local Python analysis scripts and fetches public lottery history, with no evidence of hidden data access or harmful behavior.
Install only if you are comfortable with a local Python script installing two PyPI packages, fetching lottery history from a third-party website, and saving generated CSV/JSON files in the skill folder. Treat the output as entertainment or analysis only; the artifacts correctly note that lottery results are random and not guaranteed.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
65/65 vendors flagged this skill as clean.
