Back to skill

Security audit

competition-analyzer

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward Chinese-language competitor-analysis workflow with no hidden execution, credential access, persistence, or destructive behavior.

Install this if you want a Chinese-language workflow for competitor research. Expect it to use public sources and produce a Markdown report; review any estimated market metrics or pricing because the skill itself depends on sourced or inferred business information.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The manifest description and the entire skill content are written as Chinese-only instructions, including Chinese trigger phrases and a Chinese-named deliverable format. This imposes a specific language/locale on use of the skill without any documented opt-in or alternative language option, which matches the language/locale policy violation criteria.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.