Back to skill

Security audit

AI编程工程化

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Chinese workflow guide for improving AI-assisted software engineering quality, with no hidden execution, credential use, persistence, or data exfiltration behavior found.

Install this if you want a strict Chinese-language engineering workflow for AI coding. Be aware it may trigger on broad software-quality requests and may push a rigid gate-based process; review any generated CI or project changes before running them in your repository.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger list includes very broad generic terms such as '开发流程' and '代码质量', which can match many ordinary user requests outside the skill's intended scope. This can cause unintended activation, leading the agent to inject a rigid workflow into unrelated conversations and potentially override safer or more appropriate skills.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
Forcing all output to Chinese without user choice can cause mismatches with user expectations, system language, or downstream tooling that assumes another language. In a multi-user or automation context, this may degrade safety-relevant comprehension, review quality, or interoperability rather than create direct code-execution risk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.