Back to skill

Security audit

Upwork 投标判断助手

Security checks across malware telemetry and agentic risk

Overview

This skill is a transparent Upwork bid-evaluation assistant that uses relevant job and profile information without installing code, taking account actions, or asking for credentials.

Install only if you want a Chinese-language assistant for Upwork opportunity decisions. Share only the job/profile details needed for the analysis, redact private client information and credentials, and treat its scoring and Boost advice as decision support rather than a guarantee of interviews or income.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill enables implicit invocation with no visible trigger constraints, so it may activate in conversations that merely resemble Upwork-related discussion. That can cause unintended collection or processing of sensitive profile, bidding, or client-evaluation data and may steer user decisions without an explicit request to use this skill.

Natural-Language Policy Violations

Medium
Confidence
86% confidence
Finding
The template hard-requires Chinese output ('必须按以下顺序输出') without indicating any user language preference or offering a language fallback. This can cause unintended language coercion, reducing usability and potentially leading users to misunderstand risk, bidding, or compliance advice in a security- and money-sensitive workflow.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly encourages collecting and extracting detailed freelancer profile data from public links, screenshots, copied pages, and spoken descriptions, but it does not instruct the agent to minimize collection, warn about privacy, or avoid capturing unnecessary personal data visible in screenshots or profile pages. In context, the data is relevant to the task, so this is not overtly malicious, but the absence of guardrails increases the risk of over-collection, retention, and processing of personal information beyond what is needed for bid advice.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.