Back to skill

Security audit

weekly-report-framework

Security checks across malware telemetry and agentic risk

Overview

The skill is a coherent weekly-report assistant, but it needs Review because it can collect workplace chat history and retain chat-derived records permanently.

Install only in an environment where the user has authority to process the relevant group chats and attachments. Before use, define which groups may be accessed, require approval for scheduled runs and sending, and add a retention/deletion policy for chat-derived records.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger list includes the generic term "周报" with no scoping to this specific institute, workflow, or explicit user intent to invoke the skill. That makes accidental activation likely in unrelated conversations, which is especially risky because the skill can proceed into knowledge-base access and group-chat processing workflows.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill mixes time-based automatic execution with casual mention triggers, creating ambiguous invocation boundaries. This can cause the skill to run without a sufficiently clear user action, increasing the chance of unauthorized or unintended report generation and data collection.

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill instructs the agent to fetch and analyze group chat history, including potentially up to 90 days of messages, but does not present a clear user-facing warning or consent requirement about that data collection. This is dangerous because it can lead to covert processing of sensitive employee, project, or business communications beyond what users reasonably expect.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrase "生成周报" is very generic and can plausibly appear in normal conversation, making accidental or unintended invocation more likely. In a skill that can initialize or write to a knowledge base, ambiguous activation increases the chance of unwanted file creation, workflow execution, or data handling without clear user intent.

Vague Triggers

Medium
Confidence
87% confidence
Finding
Repeating the same broad activation phrase in the conversational flow reinforces an ambiguous trigger model rather than narrowing it. Because the documented behavior includes automatic detection of a missing knowledge base and branching into setup actions, an accidental match could start side-effecting setup logic the user did not explicitly request.

Missing User Warnings

Medium
Confidence
83% confidence
Finding
The framework instructs broad ingestion and persistence of group-chat content, file summaries, and work records without any explicit privacy notice, consent boundary, minimization rule, or retention justification. In a workplace reporting skill, this creates a real risk of collecting personal or sensitive business data beyond what is necessary and retaining it indefinitely.

Ssd 3

Medium
Confidence
92% confidence
Finding
The data retention policy says group-chat capture records are kept permanently and report drafts are retained and reused across iterations. Permanent retention and reuse of chat-derived content increases the risk of sensitive information leakage, unauthorized secondary use, and overexposure if the knowledge base is later accessed by the wrong party.

Ssd 3

Medium
Confidence
95% confidence
Finding
The skill prescribes large-scale collection, summarization, and permanent storage of group-chat messages, image/file-derived content, message IDs, and project-linked records across many sections of the document. Because the context is internal project reporting, the data is likely to include sensitive operational details, employee activity traces, and attachments; permanent retention and broad extraction materially increase leakage, insider misuse, and overcollection risk.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.