Back to skill

Security audit

商业模式画布

Security checks across malware telemetry and agentic risk

Overview

This is a markdown-only Chinese business-model planning skill with no evidence of hidden execution, data access, persistence, or credential handling.

Before installing, consider that outputs are designed to be in Chinese and that generated business benchmarks, LTV/CAC estimates, and competitor comparisons are planning aids rather than authoritative financial or market facts.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The skill explicitly mandates Chinese output regardless of user preference, which can override user intent and reduce usability or accessibility for users who need another language. While this is not a code-execution or data-exfiltration issue, it is a genuine policy and safety concern because it constrains agent behavior without user opt-in.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.