Back to skill

Security audit

跨境出口认证与清关查询

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed export-compliance reference skill with no executable code, credential use, persistence, or hidden data handling.

Before relying on this skill, provide a clear product category and destination country, and verify current requirements with official authorities, a customs broker, or a certification provider because trade, customs, and platform rules change frequently.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger list contains broad phrases such as generic certification or restriction questions that can match ordinary conversation outside the intended export-compliance workflow. This can cause the skill to activate in the wrong context and deliver authoritative regulatory guidance when the user did not intend to invoke this specialized skill, increasing confusion and the chance of inappropriate downstream actions.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrase "产品认证哪里办" is highly ambiguous and could refer to many unrelated domains, including domestic licensing, education credentials, or general product advice. Because the skill provides specialized customs and export compliance outputs, accidental invocation may misroute the conversation and present irrelevant or misleading regulatory steps.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.