Back to skill

Security audit

Prompt Dog

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed prompt/workflow design skill with a bundled legal-review workflow example that is sensitive but scoped and includes human-review safeguards.

Before installing, note that the bundled contract-review asset can process sensitive legal documents. Use脱敏/test contracts first, confirm your AI platform's data-handling terms, and keep lawyer review in the loop for any real contract decision.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (10)

Description-Behavior Mismatch

High
Confidence
93% confidence
Finding
This file clearly documents a standalone commercial contract review agent, which does not match the declared skill purpose of prompt/SOP/workflow design. That mismatch can cause capability confusion and unsafe invocation, leading users or host platforms to run legal-document review behavior under a different trust and governance model than intended.

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
The documented flow instructs users to execute the review directly, bypassing the manifest’s required multiple-choice clarification behavior. This increases the chance of acting on ambiguous user intent, wrong review posture, or missing constraints such as jurisdiction, contract type, confidentiality handling, and output limitations.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
This file implements a full legal contract-review agent, which is materially outside the declared purpose of a prompt/SOP/workflow-design skill. That scope expansion can cause the host agent to perform sensitive legal-analysis tasks under the cover of an unrelated skill, bypassing user and platform expectations about what capabilities are being loaded.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
These lines explicitly instruct the agent to extract facts, identify legal risks, provide clause suggestions, and support lawyer review, granting substantive legal-analysis behavior not justified by the manifest. In context, this is dangerous because it enables domain-sensitive decision support in a skill users would invoke for prompt engineering, increasing the chance of unauthorized or unreviewed legal guidance.

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
Authorizing network retrieval of legal sources extends the skill from prompt design into live legal research, which is a distinct and sensitive capability. Within this mismatched skill context, external lookup can lend false authority to outputs and increase the risk that the agent provides quasi-legal advice based on incomplete or jurisdiction-mismatched sources.

Intent-Code Divergence

Medium
Confidence
88% confidence
Finding
The version note normalizes the file as a routine update while the underlying content is a complete contract-review specification unrelated to the skill's stated purpose. That mismatch increases concealment risk: reviewers may underestimate the change and allow sensitive capability drift into production without appropriate scrutiny.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger phrases like '复盘' and '跑回归' are broad and underspecified, which can cause accidental activation or execution in the wrong context. In an agent environment, vague operational triggers may lead to unintended access to prior data, modification workflows, or test routines without sufficient scoping or confirmation.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The skill hard-codes a language assumption from conversation language and treats it as an active output setting, which can mis-handle multilingual users or produce outputs in the wrong language without explicit consent. This is primarily a reliability and user-intent integrity issue rather than a direct security exploit, but it can cause sensitive workflows to proceed under an incorrect assumption.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The file is entirely written in Chinese and does not provide any language-choice mechanism or explain a strict locale requirement. In a prompt-engineering skill, this can cause users or downstream agents to misunderstand routing rules and safety-relevant instructions, leading to incorrect task handling or reduced usability across mixed-language environments.

Ssd 3

Medium
Confidence
95% confidence
Finding
The skill instructs the agent to fill unanswered items with recommended defaults and continue without explicit reconfirmation, which can silently convert inferred or guessed details into operative instructions. In a prompt/SOP design skill, this is more dangerous because the resulting workflow may encode incorrect assumptions, propagate user data into outputs, or trigger downstream actions based on unverified configuration.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.