Back to skill

Security audit

data-source-evaluator

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly a data-strategy template, but it explicitly tells agents to plan anti-scraping bypasses, which needs human review before installation.

Review this skill carefully before installing. It is text-only and not self-executing, but users should modify or constrain it so crawler recommendations focus on lawful, permission-based collection and explicitly reject bypassing CAPTCHAs, authentication, IP blocks, rate limits, or other site protections.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The invocation description uses broad keywords like 数据源、数据采集、数据评估、数据策略、爬虫方案 without clear boundaries, which can cause the skill to activate for requests that include sensitive or abusive data-collection scenarios. In this skill’s context, that overbroad routing is more dangerous because the workflow explicitly discusses crawling and collection strategy, increasing the chance it will be used to facilitate questionable scraping or compliance-unsafe guidance.

Natural-Language Policy Violations

High
Confidence
97% confidence
Finding
The workflow explicitly includes 反爬绕过 as part of the crawler plan, which normalizes anti-bot evasion guidance without a tightly justified defensive or research context. This is dangerous because it can directly assist users in bypassing access controls or site protections, and the surrounding skill is operationally focused on data acquisition, making misuse more likely rather than merely theoretical.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.