Back to skill

Security audit

竞品分析专家

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent competitor-analysis guide that uses public research and structured reporting, with only minor usability concerns around broad triggers and Chinese-only output.

Before installing, be aware that the skill may trigger on broad market-research or business-analysis requests and will default to Chinese output. It is otherwise limited to public competitor research and structured reporting; avoid providing confidential internal strategy unless you intend it to be used in the analysis prompt.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger list in the metadata is very broad and includes common business terms such as 市场调研、商业分析、行业研究 and SWOT分析. This can cause the skill to activate outside the user's actual intent, leading to prompt hijacking of general business conversations and unintended routing into a rigid workflow that may fabricate competitive-analysis content or force web-search behavior.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The markdown trigger conditions are ambiguous because many conditions are single keywords or broad topic classes, and the exclusion set is too limited to counterbalance them. In practice this increases accidental invocation risk and may override normal assistant behavior for loosely related requests, especially around market research and product advice where user intent may not actually be competitor analysis.

Natural-Language Policy Violations

Medium
Confidence
83% confidence
Finding
Forcing Chinese output without user choice can create a control-boundary issue where the skill overrides user language preference or downstream system expectations. While not directly enabling code execution or data exfiltration, it can degrade usability, cause misunderstandings in multilingual contexts, and interfere with safe handling if the user requested another language for precision or compliance reasons.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.