程序员客栈任务

Security checks across malware telemetry and agentic risk

Overview

This is a text-only Chinese guide for using a freelancing platform; it raises privacy cautions but does not run code or collect data itself.

Install only if you want a manual guide for using Proginn. Do not share ID documents, account credentials, payment details, or private contact information with the agent; complete verification only through the official Proginn website or app. Prefer platform messaging, contracts, and payment protections before moving communication or payment off-platform.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill explicitly instructs users to include external contact details such as WeChat and email in service descriptions, which can encourage sharing personal information outside the platform's protected workflow. In the context of a freelancing marketplace, this can bypass platform safeguards, increase privacy exposure, and create opportunities for fraud, off-platform solicitation, or social engineering.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal