Back to skill

Security audit

activity-planner

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent Chinese event-planning assistant that generates a local HTML report, with no hidden code execution, credential access, network use, or persistence found.

Before installing, expect Chinese-language output and a generated HTML file in your current workspace. Review any generated event plan for consent, privacy, and lawful-contact requirements before using recommendations involving attendee photos, phone calls, QR-code lead capture, or follow-up outreach.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are broad, generic requests such as '活动策划' and '活动方案', which can easily overlap with normal user conversation and unintentionally invoke the skill. In an agent environment, over-broad routing can cause the wrong skill to activate, exposing user input to an unnecessary prompt context and producing unintended actions or outputs.

Natural-Language Policy Violations

Medium
Confidence
75% confidence
Finding
The README presents the skill entirely in Chinese and describes Chinese trigger phrases without indicating any language negotiation or user choice. This can create usability and safety issues in multilingual environments, where users may receive prompts or outputs in an unexpected language and misunderstand important planning details, constraints, or generated content.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrases are broad enough to match ordinary user requests about planning activities, which can cause the skill to activate when the user did not clearly intend to invoke it. In context, this increases the chance of unsolicited workflow takeover and downstream actions such as structured data collection or file-generation behavior being initiated without explicit user consent.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill instructs saving an HTML file directly into the user's current working directory without first warning the user or obtaining explicit confirmation. In context, this is risky because broad triggers could lead to unanticipated filesystem writes, causing user surprise, workspace pollution, or accidental overwriting if naming collisions or unsafe path handling occur elsewhere in the implementation.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The guidance explicitly recommends '扫码留资机制' for lead capture but provides no instruction to obtain informed consent, disclose purpose, limit collection, or protect the data. In an activity-planning skill, this omission can directly propagate privacy-noncompliant practices into real-world event execution, leading to unauthorized collection or misuse of attendee personal information.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The framework instructs planners to photograph participants and distribute photos/records afterward without any warning about privacy, consent, or image-rights implications. Because this skill is meant to generate operational event plans, users may reproduce this guidance verbatim, causing unauthorized capture or sharing of participant images and related personal data.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The guidance recommends calling attendees who have not arrived, but it gives no reminder to ensure prior consent, lawful contact basis, or safe handling of phone numbers. In an activity-planning skill that may be used at scale for event operations, this can normalize privacy-noncompliant outreach and lead to misuse of personal contact data, complaints, or regulatory exposure.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.