Back to skill

Security audit

HR谈心罗盘

Security checks across malware telemetry and agentic risk

Overview

This is a prompt-only HR coaching skill whose sensitive HR handling is disclosed and scoped, but users should apply their own privacy, consent, and jurisdiction controls.

Install only if you intend to use a Chinese HR/OD coaching workflow. Do not paste real names, contact details, health records, compensation details, chat screenshots, or other sensitive employee data into an AI system. Use employee codes, approved storage, limited access, retention/deletion rules, and local HR/legal guidance, especially for labor disputes, health issues, harassment, discrimination, or psychological-crisis signals.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The README states the agent will automatically load this skill when conversations involve broad HR topics like employee check-ins or one-on-ones. That creates prompt-scope overreach: the skill may activate in routine workplace discussions without explicit user consent, injecting its guidance and assumptions into unrelated contexts. In an HR setting, this is moderately risky because the skill shapes sensitive employee conversations and organizational judgments.

Natural-Language Policy Violations

Medium
Confidence
80% confidence
Finding
The skill hardcodes that all advice should conform to 'common knowledge of Chinese labor law' without requiring user opt-in or checking jurisdiction. If used outside China or by users who have not requested China-specific guidance, the model may provide legally incorrect or misleading recommendations in sensitive HR matters such as retention, transfers, or exits. The HR context increases danger because users may rely on the output for employment decisions affecting real people.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The workflow explicitly tells HR users to write down employee conversation details, preserve verbatim quotes, and archive files for later AI analysis and quarterly aggregation, but it provides no guidance on consent, minimization, access control, retention, or handling of highly sensitive personal data. In an HR context, these records can contain health, mental state, family, relationship, performance, and resignation-risk information, so indiscriminate recording and AI feeding creates substantial privacy, compliance, and insider-misuse risk.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The prompt hard-requires '全中文' output, which overrides user language preference and can reduce user control or accessibility. While not a direct security exploit, it is a genuine policy/quality weakness because instruction rigidity can cause unsafe or unusable behavior for users who need another language for comprehension, review, or escalation.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The prompt hard-codes '全中文' for all interactions without checking the user's language preference. This can override user intent, reduce transparency for users expecting another language, and increase the risk of misunderstanding in sensitive HR conversations where precision matters.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.