Back to skill

Security audit

产业投资分析师

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate investment-analysis skill, but it automatically stores and reuses potentially confidential deal analysis without clear user consent or retention controls.

Install only if you are comfortable with the skill saving investment analyses and reusable notes locally. Avoid using it with confidential deal materials unless you disable or tightly control memory writes, review what is saved, and confirm before exporting reports to external tools such as Tencent Docs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (8)

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The skill instructs the agent to read and write persistent memory and self-improvement files that are not necessary for the core investment-analysis function. This expands the agent’s data access and retention surface, increasing the risk of cross-session data leakage, unintended persistence of sensitive user information, and prompt-driven state manipulation via external files.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The skill declares limited data sources and a scoped analysis-history feature, but separately instructs the agent to read and write an external self-improving memory file. That creates an undeclared persistence and retrieval channel outside the stated feature boundary, which can silently retain or reuse prior task content and undermine user expectations about where data is stored.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
A generic persistent-learning mechanism is unrelated to the core purpose of investment analysis and gives the agent an open-ended channel to accumulate and reuse information across tasks. In a domain that may involve confidential deal materials, this increases the risk of sensitive data retention, cross-project leakage, and behavior drift beyond the skill's stated function.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger scope is very broad, covering multiple adjacent business tasks such as investment analysis, founder assessment, government招商 evaluation, competitor comparison, and report export. In agent platforms that auto-route by description, overbroad activation can cause this skill to run on unintended prompts, leading to inappropriate data collection, overconfident investment-style recommendations, or use of integrated browsing/data sources in contexts the user did not intend.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill says every analysis is automatically saved to local memory files, but it does not provide a clear warning, opt-in, or control over that persistent write. Because investment analyses may contain nonpublic company, founder, financial, or diligence information, silent storage increases privacy, confidentiality, and data-retention risk.

Ssd 3

Medium
Confidence
94% confidence
Finding
The skill explicitly directs the agent to persist user facts, preferences, corrections, and project context into files across sessions. In an investment-analysis context, those notes may contain sensitive business, personal, or strategic information, so retaining them in natural-language files creates a meaningful confidentiality and data-minimization risk and can expose future sessions to unintended disclosure or prompt contamination.

Ssd 3

Medium
Confidence
97% confidence
Finding
The analysis-history feature persistently stores project names, investment conclusions, risks, and source details, then reuses them in later sessions without any consent, sensitivity classification, or minimization controls. In an investment context, this can capture confidential pipeline information and enable unauthorized reuse or disclosure across users, projects, or future tasks.

Ssd 3

Medium
Confidence
96% confidence
Finding
The self-improving instructions tell the agent to write reusable lessons after corrections or failed attempts to a separate memory location, but place no limits on what may be recorded. That creates an unscoped persistence channel likely to absorb sensitive user inputs, proprietary diligence context, or confidential error details, and later surface them in unrelated tasks.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.