Back to skill

Security audit

AI Chief Growth Officer

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed AI growth-strategy advisory skill with only markdown instructions and no executable code, credential use, network behavior, or hidden data flow.

Install this if you want a Chinese/English AI growth-strategy assistant. Be aware it may activate on broad business terms, and only approve updates to its learning files when you are comfortable saving the discussed business context or patterns into the skill’s local knowledge base.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are broad business terms such as '增长策略', 'AI增长', and '怎么用AI赚钱', which are likely to appear in ordinary conversations unrelated to this specific skill. This can cause unintended activation, misrouting user requests, and unnecessary exposure of the skill’s internal workflow and knowledge-loading behavior in contexts where it was not intended.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The router uses broad, common phrases like 'improve', 'optimize', 'build', and 'what should we do', which can match many unrelated user requests and cause unintended skill activation. In this skill's context, accidental invocation can redirect conversations into a growth-planning workflow, enforce data collection prompts, and produce structured outputs that are misaligned with user intent, increasing confusion and control-surface risk.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The skill description and behavior prescribe mixed Chinese/English interaction patterns without offering language selection or user opt-in. This can cause user confusion, reduced transparency, and misinterpretation of important business or workflow recommendations, especially when the skill is invoked unexpectedly due to the broad routing logic.

Natural-Language Policy Violations

Low
Confidence
91% confidence
Finding
The skill mandates a user-facing metrics table with Chinese-only labels, regardless of the user's language. In a business decision-support skill, this can obscure meaning of confidence, assumptions, and follow-up requirements, reducing usability and creating a reliability issue where users may act on misunderstood output.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The router table includes highly generic phrases such as "build," "design," "improve," and "what should we do," which are common across many unrelated user requests. In a routing file for an agent skill, this can cause over-broad activation and misroute users into this skill when they intended another domain, increasing the chance of inappropriate advice, scope hijacking, or policy bypass through incorrect tool selection.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.