Back to skill

Security audit

A股情报调查员

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed research assistant, but it automatically sends every generated investigation report to RedFox with an API key and lacks clear per-report consent or retention controls.

Review before installing. Use this only if you are comfortable with full investigation reports being sent to and stored by RedFox. Avoid confidential, regulated, personal, or sensitive business investigations unless you understand RedFox access, retention, deletion, and API-key revocation controls.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The workflow explicitly requires every generated investigation report to be uploaded to an external Redfox platform, extending the skill from local analysis into mandatory third-party data exfiltration. Because the reports can contain sensitive business research, personal background information, or user-supplied confidential data, automatic transmission creates a clear confidentiality and unauthorized data-sharing risk.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The documentation adds a capability to use an API key and transmit full report contents to an external service, which is broader than the stated intelligence/research purpose and introduces secret-handling plus outbound data-transfer risk. This can expose both sensitive report data and platform credentials, especially if the skill is used on investigations involving private or regulated information.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill says users can simply describe their needs in natural language with no fixed commands, which creates very broad invocation semantics. In agent environments, this can cause the skill to activate for loosely related prompts and unnecessarily access external investigation capabilities or sensitive market-research workflows when the user did not explicitly intend to invoke this skill.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The example trigger phrases are short, generic requests like 'Investigate a competitor' or 'Verify information,' which are common in everyday conversation and can overlap with many unrelated tasks. This increases the chance of accidental or over-broad invocation, leading the agent to perform external searches, analysis, or reputation/background investigations without sufficiently precise user consent or scope.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The invocation guidance uses very broad natural-language triggers such as '调查一下', '追踪', and '验证', which overlap with common conversational requests. This can cause the skill to activate unintentionally in unrelated contexts, routing sensitive user queries into an external investigation workflow and potentially increasing unnecessary data collection or disclosure to third-party sources.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger list is very broad and includes generic phrases like '财报分析', '竞品分析', '背景调查', and '多源搜索', which can overlap with ordinary user requests and cause the skill to activate unintentionally. In this skill's context, unintended activation is more dangerous because the skill is configured to perform broad investigation workflows and automatically save resulting reports to an external platform, increasing the chance of unnecessary data collection and external disclosure.

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill states that every investigation report is automatically saved to the RedFox platform, but it does not present a prominent, explicit user warning or consent step about external data transfer, retention, and privacy implications. This is especially risky because the skill supports background investigations, rumor verification, and company/person inquiries that may include sensitive, proprietary, or personal information, which could be transmitted off-platform without informed user approval.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The markdown directs automatic upload of reports to an external platform without a clear user-facing warning that data will leave the system. In this skill context, reports may contain sensitive corporate intelligence, personal background findings, and unverifiable allegations, so silent transmission materially increases privacy, confidentiality, and compliance risk.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.