Back to skill

Security audit

进口产品核查

Security checks across malware telemetry and agentic risk

Overview

This skill is for product-verification research, but it automatically saves a local evidence package that can include personal purchase and payment materials without a clear opt-in.

Review before installing. Use this skill only if you are comfortable with product photos, purchase receipts, screenshots, and possible payment-record images being saved locally under ~/.qclaw/workspace. Redact personal or financial details before providing documents, and delete the evidence package after the investigation if you do not need it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The skill instructs automatic local persistence of user-provided images into an evidence package, which materially expands data handling beyond the stated public-information investigation purpose. This creates an unnecessary retention surface for potentially sensitive user data and can surprise users who only expected online verification, increasing privacy and data-governance risk.

Description-Behavior Mismatch

Medium
Confidence
97% confidence
Finding
This section operationalizes automated filesystem writes, screenshot capture, directory creation, and report generation, none of which are clearly bounded by the skill's high-level description. Because the workflow stores raw evidence and derived reports by default, it increases the chance of over-collection, unintended retention, and exposure of sensitive personal or commercial information on disk.

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The skill specifically collects and stores receipts and payment records, which often contain personal identifiers, transaction details, and account metadata. For import-product investigation, these materials may sometimes be useful for later disputes, but they are not always necessary for the core verification task, so default retention is disproportionate and raises privacy risk.

Missing User Warnings

High
Confidence
98% confidence
Finding
The skill says user-uploaded images should be immediately saved to a local evidence directory without first informing the user or obtaining consent. Silent persistence of uploaded materials is dangerous because images may contain personal information, order data, location clues, or other sensitive context, and users may reasonably expect transient processing rather than local retention.

Missing User Warnings

High
Confidence
98% confidence
Finding
The evidence-package workflow stores receipts, payment records, and screenshots locally throughout the investigation, but it lacks a clear warning about sensitivity, storage scope, access controls, or retention period. This can expose financial and personal data if the workspace is shared, backed up insecurely, or later accessed by other processes or users.

Ssd 3

Medium
Confidence
95% confidence
Finding
Default instructions to persist and organize user evidence create a standing data-retention mechanism that is not strictly required for every investigation. Even if intended to help users preserve proof, automatic evidence packaging increases exposure of sensitive content and broadens the blast radius of any local compromise.

Ssd 3

High
Confidence
98% confidence
Finding
This section defines a systematic workflow for continuous collection and retention of sensitive materials during the investigation, including screenshots and transaction artifacts. Because the process is automatic and cumulative, it can create a rich dossier about the user and their purchases, making any accidental disclosure or unauthorized access more harmful.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.