Back to skill

Security audit

Cue 深度研究(通用版)

Security checks across malware telemetry and agentic risk

Overview

This is a legitimate Cue research integration, but it needs Review because broad prompts and local mimic documents can be sent to a remote service without clear enough privacy and activation boundaries.

Install only if you are comfortable sending research prompts, API credentials for Cue authentication, and any mimic documents you explicitly choose to Cue's service. Avoid using --mimic-file with confidential, personal, regulated, or proprietary documents unless you have confirmed Cue's handling, retention, and deletion policies.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill claims it does not perform local retrieval, yet the documented workflow explicitly reads local files such as ~/.cue/config.json and supports --mimic-file with local document paths. This is dangerous because users may be misled into believing no local data is accessed or transmitted, reducing informed consent around API key handling and local document exposure to the remote Cue service.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The metadata description advertises extremely broad applicability for 'any financial/business/industry research question,' which can cause overbroad or accidental activation by an agent. In agent environments, ambiguous trigger scope increases the chance that sensitive user prompts or unrelated tasks are routed to this remote skill without deliberate user intent.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The introduction says 'any question can run,' which is ambiguous trigger language that encourages use outside clearly bounded scenarios. In a tool-using agent, this broad scope can lead to unintended transmission of user content to a third-party service and makes least-privilege tool selection harder.

Vague Triggers

Medium
Confidence
81% confidence
Finding
The example prompts portray the skill as suitable for a very wide range of research requests without clarifying activation boundaries or data-sensitivity constraints. This increases the risk of users or orchestrators treating it as a default catch-all research tool and forwarding sensitive queries to the external provider.

Missing User Warnings

High
Confidence
98% confidence
Finding
The skill supports mimicry from a local file path, including PDFs or Word documents, but does not warn that the contents may be transmitted to a remote service for style analysis. This creates a substantial risk of exfiltrating confidential documents, internal reports, or personal data under the guise of formatting or writing-style assistance.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.