Back to skill

Security audit

技能选择器

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a skill-selection helper with minor usability and activation-scope risks, not evidence of malicious behavior.

Install only if you are comfortable with a Chinese-language skill-selection helper that may activate on broad skill-choice phrasing; review its recommendations before letting the agent load or act through another skill.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases include very broad everyday language such as “该用什么” and “帮我选技能”, which can cause the skill to activate in contexts where the user did not explicitly intend to invoke a skill-selection workflow. In an agent environment, this increases the risk of unintended interception of user requests and misrouting to this skill, especially because the skill then scans installed skill descriptions and influences downstream skill loading.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
Forcing Chinese-only output without checking the user's language can create unsafe or misleading interactions if the user cannot understand recommendations, confirmations, or limitations. While not a direct code-execution issue, it can degrade informed consent and increase the chance of incorrect skill selection or accidental execution in multilingual environments.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.