Back to skill

Security audit

data-analysis-skills

Security checks across malware telemetry and agentic risk

Overview

This is a text-only Chinese spreadsheet analysis skill that is purpose-aligned, with caution needed around detailed reasoning output and sensitive tables.

Use this skill for spreadsheet or CSV analysis you are allowed to share. Avoid requesting hidden chain-of-thought; ask for concise rationale, formulas, and row-level evidence instead. Review any HR, finance, legal, or compliance conclusions before acting on them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Natural-Language Policy Violations

High
Confidence
98% confidence
Finding
This instruction explicitly tells the skill to expose chain-of-thought reasoning to users. Revealing internal reasoning can leak hidden policy logic, sensitive intermediate data, and make prompt-injection or model-extraction attacks easier by showing how the model reasons and what tools or checks it used.

Natural-Language Policy Violations

High
Confidence
99% confidence
Finding
The document repeatedly mandates showing each reasoning step, accessed ontology objects, and functions used. In this data-analysis context, that increases risk of exposing sensitive schema details, internal decision rules, and intermediate data transformations that should remain internal, especially when user-provided tables may contain regulated or confidential information.

Natural-Language Policy Violations

High
Confidence
99% confidence
Finding
The required output format forces every conclusion to include explicit step-by-step reasoning, which operationalizes routine chain-of-thought disclosure rather than leaving it optional. Because this skill handles uploaded tables/CSV/Excel and encourages line-level provenance, the combination can amplify leakage of sensitive intermediate inferences and make the model's internal safeguards easier to probe and bypass.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger scope is extremely broad: it fires not only on explicit data-analysis requests but also on vague everyday phrases like '帮我看看' or '这数据对不对' whenever tabular content is present. This can cause the skill to activate in many ambiguous contexts, increasing the chance of inappropriate data ingestion, unnecessary processing of sensitive spreadsheet content, and interference with more appropriate specialized skills or safer default handling.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The skill metadata is written to operate in Chinese without any user opt-in or locale negotiation, which can force responses or analysis behavior into a language the user did not request. In security-sensitive data handling, this raises the risk of misunderstanding user intent, misinterpreting consent around sensitive fields, and producing inaccessible or misleading output.

Natural-Language Policy Violations

High
Confidence
99% confidence
Finding
The eval explicitly checks for 'CoT 思维链', which pressures the model to reveal internal chain-of-thought rather than just concise reasoning summaries. Requiring hidden reasoning disclosure is dangerous because it can train or incentivize agents to expose internal deliberations, making prompt extraction and policy-bypass attempts easier and conflicting with safe model behavior.

Natural-Language Policy Violations

High
Confidence
99% confidence
Finding
This second eval also requires the output to include chain-of-thought, again creating a direct incentive for the skill to disclose internal reasoning traces. In a data-analysis skill, this is especially risky because the model may mix sensitive user data into verbose reasoning and normalize unsafe disclosure patterns across many tasks.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger examples in this range are broad and colloquial, such as asking whether two columns 'have a relationship' or whether data 'looks suspicious,' without requiring clear evidence that structured data is actually present. That can cause the skill to activate on ambiguous everyday requests, leading to misrouting, unnecessary access to attached/local files, or over-collection of user data beyond the user's intent.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.