Back to skill

Security audit

自媒体趋势分析

Security checks across malware telemetry and agentic risk

Overview

This is a low-risk Chinese-language advice skill for self-media content strategy, with no code or system access.

Installers should treat this as general creator-strategy advice, not authoritative or current market research. The main limitations are that it is Chinese-language and may activate on broad content-planning prompts; there is no evidence of technical system risk in the package itself.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The description uses broad trigger examples like “做什么自媒体” and “自媒体趋势” without defining clearer boundaries for when the skill should activate. In an agent environment, this can cause over-triggering on loosely related user queries, leading to inappropriate routing, unexpected behavior, or crowding out more suitable skills, though it does not directly enable code execution or data exfiltration.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The skill content and description are entirely in Chinese and implicitly constrain behavior to Chinese without indicating language adaptation based on user preference. In a multilingual agent, this can degrade usability, cause mismatched responses, and trigger the skill for users who did not opt into Chinese, but it is not inherently a high-severity security issue.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal