Back to skill

Security audit

上门体育-多平台自动回复

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed auto-reply template and helper, with no evidence of hidden account access, credential use, persistence, or data exfiltration.

Safe to install as a template/helper. Before using its generated replies in live accounts, review them for accuracy, platform-policy compliance, truthful claims, and whether they ask customers for personal contact details or addresses.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are broad terms like `自动回复`, `设置回复`, `客服话术`, and `评论回复`, which can match many ordinary messaging or support requests and cause the skill to activate unexpectedly. In an agent environment, overbroad activation can route unrelated conversations into sales-oriented or automation guidance, increasing the risk of unintended actions, policy bypass in context, or user confusion.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.