Back to skill

Security audit

user-need-miner

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward Chinese-language user-research helper, with its main caveat being that it may use web search to gather public user comments when the user has not provided source data.

Before installing, be aware that if you do not provide raw interview or feedback data, the skill may ask the agent to search public websites and summarize public user comments. Avoid including private, sensitive, or regulated personal data unless you intend it to be used for the analysis.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Confidence
87% confidence
Finding
This markdown skill directs the agent to collect public information from social media, forums, app store reviews, and other sources when the user has not provided raw data. The description does not include any warning that external data collection may involve transmitting queries to third-party services or processing personal data from online sources.

Natural-Language Policy Violations

Low
Confidence
81% confidence
Finding
The natural-language content, including the description, title, workflow, and trigger phrases, is entirely in Chinese. There is no indication that users may choose another language or that the Chinese-only constraint is intentional and justified for a region-specific skill.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.