Back to skill

Security audit

Report Tracker

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed report-tracking workflow that reads research material and appends analysis to local investment-tracking files, with no evidence of hidden, networked, destructive, or credential-related behavior.

Install this if you want a Chinese-language workflow that automatically appends research-report analysis into local investment tracking files. Be aware that report-like file, link, or text analysis requests may cause local archive updates, so review the target paths and consider asking the agent to confirm before writing if you use it outside that exact workflow.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger description is broad enough to activate on generic mentions like files, links, or requests to analyze text, which can cause the skill to run outside its intended scope. In a file-writing skill, over-triggering is dangerous because it may process unrelated user content and append or modify tracking archives without sufficiently specific user intent.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The skill description mandates Chinese-language behavior without checking the user's preferred language, which can lead to misunderstanding of confirmations, receipts, and archived content. In this context, that increases operational risk because the skill performs structured analysis and writes persistent records; language mismatch can cause users to miss what was stored or approved.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.