Back to skill

Security audit

Last 30 Days—CN版

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Chinese social-media research skill that sends chosen topics to external research services and creates reports, with some consent and documentation gaps but no evidence of hidden or malicious behavior.

Install only if you are comfortable sending research topics, brand names, or competitor queries to RedFox and web search providers. Use your own revocable REDFOX_API_KEY, avoid confidential or personal data in prompts, and expect local JSON/HTML reports to be written and the HTML report to be opened automatically.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The README explicitly says the skill includes a built-in free public key while also discussing key-handling hygiene. A built-in shared/public API key is a real security weakness because it invites credential reuse, uncontrolled third-party use, quota exhaustion, abuse attribution to the skill/provider, and possible key leakage through redistribution or logs.

Context-Inappropriate Capability

Low
Confidence
92% confidence
Finding
The skill instructs the agent to automatically open a generated local HTML file via `open`, which triggers a local application launch without explicit user consent. Even if the HTML is locally generated, it is derived from external data and may contain active content or unexpected links, expanding the attack surface beyond the stated research task.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The invocation guidance says users can simply describe what they want in natural language, without clear boundaries or confirmation requirements. In agent environments, overly broad triggers increase accidental invocation, unintended external searches, and data exposure to third-party services when ordinary conversation matches the skill's activation pattern.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The example phrases are common conversational requests such as 'Research AI video tools for me' and 'Generate an HTML visualization report.' Because these resemble ordinary user dialogue, they can cause ambiguous routing or accidental tool activation, which may lead to unintentional web queries or file generation.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill is invoked via broad natural-language requests without a narrowly scoped trigger boundary, which increases the chance of accidental activation and unintended transmission of user queries to external research services. In a tool that performs web/platform research and pre-searches, this can cause privacy leakage or unexpected external calls from ordinary conversation that merely mentions related topics.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The README describes collecting data from Xiaohongshu, Douyin, WeChat public accounts, and a pre-research WebSearch step, but it does not clearly warn users that their prompts/keywords may be transmitted to external platforms and APIs. This creates a meaningful privacy and compliance risk because users may submit sensitive brand, business, or personal topics believing the analysis is local.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill performs local file creation and then launches the resulting file without clearly warning the user or obtaining opt-in. This weakens user control and could surprise users with filesystem writes and browser/app execution, especially because the report contents are influenced by externally sourced data.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The default prompt is very broad and lacks activation boundaries, exclusions, or specificity about when the skill should be used. In an implicitly invocable agent ecosystem, this increases the chance the skill is selected for loosely related requests and may collect or synthesize external social-media research when the user did not clearly ask for it, creating scope creep and possible privacy or policy issues.

Vague Triggers

High
Confidence
96% confidence
Finding
Enabling implicit invocation without explicit activation constraints allows the skill to be auto-selected based on broad semantic similarity rather than clear user intent. Because this skill performs cross-platform social-media research, unintended invocation could cause unnecessary external data access, over-collection of information, or responses shaped by platform-monitoring behavior the user did not knowingly request.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The script sends the user-supplied keyword and a source label to a third-party service at redfox.hk, but the code does not present a clear, explicit privacy warning at the point of use. In a research tool, queries may contain sensitive business topics, brand-monitoring targets, or internal investigation terms, so silent transmission can leak operationally sensitive information to an external provider.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.