Engineering

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only Chinese engineering guidance skill with safety-sensitive advice, but no hidden code, installer, credential access, or persistence.

Install only if you want Chinese-language engineering guidance. Treat outputs as advisory, confirm project jurisdiction, code versions, units, and assumptions, and require a qualified local professional for structural, electrical mains, gas, pressure, permitting, or other safety-critical work.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger section is very broad and overlaps heavily with ordinary engineering conversations such as calculations, material selection, standards, drawings, estimates, QA, and safety. In an agent environment, this can cause unintended invocation on routine queries, routing users into a high-authority engineering skill when they did not explicitly request it, increasing the chance of unsafe or jurisdiction-mismatched guidance.

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
The skill hard-codes Chinese standards and a Chinese-language/regulatory context without first establishing the user's jurisdiction, applicable code set, or preferred language. For engineering and construction advice, applying the wrong legal and technical standard can directly lead to unsafe designs, failed inspections, or noncompliant work, especially in safety-critical domains.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal