China Cost Estimation

Security checks across malware telemetry and agentic risk

Overview

This is a local China construction-cost estimation skill with no evidence of hidden data access, network activity, persistence, or destructive behavior.

Reasonable to install if you need China construction cost estimates. Treat outputs as advisory, verify current standards and rates before financial decisions, and be aware that strict JSON parsers may require removing the manifest BOM.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
82% confidence
Finding
The trigger phrases are very broad, covering generic terms like cost estimation, fee calculation, budgeting, and standards queries, which can cause the skill to activate for ordinary finance, procurement, or non-construction requests. Overbroad activation can route users into a region-specific workflow unexpectedly, increasing the chance of irrelevant or misleading outputs and unintended file/resource use by the agent.

VirusTotal

67/67 vendors flagged this skill as clean.

View on VirusTotal