Back to skill

Security audit

缺陷猎人

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent bug-analysis helper with optional Jira and ZenTao integration examples, and no hidden install-time or persistent behavior was found.

Installers should treat the Jira and ZenTao sections as capable of external data exchange if configured. Use only scoped API tokens, confirm before creating or syncing bug records, and avoid sending sensitive logs or internal incident details unless that is intended for the target tracker.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill includes external Jira/禅道 integrations that use API tokens and can retrieve or create bug records, but it does not clearly disclose to the user that data may be sent to third-party systems or that credentials will be used. This creates a real risk of unintended data exfiltration or unauthorized external side effects, especially if users provide sensitive logs, stack traces, or internal incident details for analysis.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.