Back to skill

Security audit

报价单生成

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed quotation-spreadsheet helper that reads user-provided price lists/templates and writes a filled Excel quote, with no evidence of hidden execution or data exfiltration.

Install if you want an assistant for filling quotation Excel files from your own price lists. Before using it, make sure the uploaded spreadsheet is the intended material price list and template, since the skill may use the most recent uploaded file as a template if one is not explicitly provided.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The skill metadata and description define very broad trigger scenarios and keywords around quotation generation without clear activation constraints, which can cause the agent to invoke this skill for loosely related requests. Over-broad activation can misroute user tasks, causing unintended file processing or data handling involving uploaded spreadsheets and pricing data.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.