Back to skill

Security audit

合同审查助手

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Chinese contract-review helper with no executable code, network behavior, persistence, or hidden access, though users should treat its legal output as non-lawyer guidance.

Install only if you want a Chinese-language assistant for preliminary contract risk review. Do not treat its signing recommendation as legal advice, and avoid sharing sensitive contracts unless you intend the agent to analyze them; for important, cross-border, or disputed contracts, consult a qualified lawyer.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger list contains broad, natural phrases such as “帮我看看合同”, “这个合同能签吗”, and “帮我审一下”, which are likely to appear in ordinary conversation and can cause the skill to activate unintentionally. Because this skill processes sensitive legal text and gives contract-signing recommendations, accidental invocation can expose private documents to the skill and steer users into a legal-analysis flow they did not explicitly request.

Natural-Language Policy Violations

Medium
Confidence
83% confidence
Finding
Forcing Chinese-only output without checking the user’s preferred language can lead to misunderstandings, especially for bilingual, cross-border, or non-Chinese-speaking users reviewing legal obligations. In a contract-review context, language mismatch is safety-relevant because users may misinterpret risk ratings, clause edits, or signing recommendations.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.