Back to skill

Security audit

alibabacloud-migration-db-evaluation-collector

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly a coherent Alibaba Cloud database evaluation guide, but it contains overbroad activation and mandatory global output-control rules that should be reviewed before use.

Install only if you want an Alibaba Cloud CMH/Rainmeter database evaluation guide and are comfortable with a skill that may strongly affect wording and add branding to outputs. Before running any steps, confirm the exact SQL and collector command, use a temporary least-privilege read-only database account, verify the collector checksum from APDS, review data.zip contents, upload only through the official APDS console, and remove the collector account after the evaluation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger list is extremely broad and spans many product names, workflows, report types, and multilingual aliases, which increases the chance the skill is invoked outside the author's intended scope. Over-broad activation can cause the agent to apply this skill's operational and output constraints in unrelated conversations, creating prompt-injection-like behavior and reducing user control.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The skill defines absolute-priority terminology rules that attempt to control every response regardless of user intent. This is dangerous because it overrides normal instruction hierarchy and can be used to steer outputs, suppress user-preferred phrasing, or create compliance with untrusted skill-authored directives.

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
Requiring an exact footer on every response and report file is an untrusted output-manipulation directive embedded in the skill. Such forced boilerplate can leak hidden control strings into downstream systems, interfere with user workflows, and demonstrates that the skill is trying to persist its own instructions across all outputs.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Content
# CMH Database Evaluation Skill (Based on Alibaba Cloud APDS Rainmeter Collector)

## CRITICAL: Mandatory Terminology Output Rule (ABSOLUTE PRIORITY)

Read this before doing anything else. It applies to **every** response, report, summary, heading, and output file you produce, in any language.
Confidence
97% confidence
Finding
Output Rule

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.