Back to skill

Security audit

brainstorming

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed brainstorming and design-approval workflow with broad activation phrases, but it does not contain hidden execution, credential access, network use, or destructive behavior.

Install this if you want a Chinese-language brainstorming and design-approval workflow. Review the trigger list first, because generic terms like design, idea, and creativity may cause the workflow to start when you only meant a normal coding request; also expect it to create or update design record files in your project.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Vague Triggers

Medium
Confidence
96% confidence
Finding
The trigger list includes broad everyday terms such as '设计', '想法', and '创意', which are likely to appear in normal user requests unrelated to this skill. That can cause unintended invocation of the brainstorming workflow, altering agent behavior and potentially interfering with other safer or more appropriate skills.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The standalone phrase 'NO CODE BEFORE DESIGN APPROVAL' is not itself dangerous, but in this skill context it reinforces a mandatory workflow that may activate on generic requests due to broad triggers. When paired with accidental invocation, it can unnecessarily block normal coding tasks and create denial-of-service-like friction in agent operation.

Natural-Language Policy Violations

Medium
Confidence
81% confidence
Finding
The skill description is Chinese-only and the body is written entirely in Chinese without offering language negotiation. In multilingual environments this can cause incorrect interpretation, user confusion, or silent workflow misapplication, especially if the skill is auto-invoked for users operating in other languages.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
98% confidence
Finding
The trigger '设计' is extremely short and semantically broad, making accidental matches highly likely in ordinary conversations about planning or implementation. Because this skill imposes a hard gate before coding, unintended activation can disrupt normal execution and override user expectations.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
98% confidence
Finding
The trigger '想法' is a common everyday noun and is too ambiguous to safely use as an activation phrase. It can capture many unrelated requests, causing the agent to enter a structured ideation-and-approval flow when the user did not intend that behavior.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
97% confidence
Finding
The trigger '创意' is overly generic and likely to overlap with benign conversational content. In this skill, accidental invocation is more concerning because it can force a multi-phase process and approval gate that changes the agent's response pattern without clear user consent.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.