Back to skill

Security audit

竞品分析专家

Security checks across malware telemetry and agentic risk

Overview

This skill is a competitor-analysis assistant that appears limited to public research guidance and structured reporting, with only minor routing-scope caveats.

Safe to install for competitor and market-analysis workflows. Be aware it may activate on broad business-research prompts, so use explicit wording when you do or do not want a competitor-analysis report, and avoid providing confidential strategy unless you intend it to be included in the analysis context.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The metadata trigger list is very broad and includes common business-analysis phrases such as 市场调研, 商业分析, and 行业研究, which can cause the skill to activate for generic requests outside its intended scope. Over-broad routing can misapply this skill, crowd out better-matched skills, and push users into a fixed workflow or tool usage pattern without clear consent.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The activation conditions include ambiguous prompts like XX和YY哪个好, 替代品, 定价策略, and 商业模式分析, which do not necessarily mean the user wants a competitor-analysis workflow. This creates prompt-routing ambiguity, increasing the chance of accidental invocation and irrelevant or overreaching analysis behavior.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.