Skill结构拆解引擎

Security checks across malware telemetry and agentic risk

Overview

This is a narrow task-decomposition prompt with only Markdown files and no code, credentials, persistence, or system access.

Install only if you are comfortable using a Chinese-language orchestration helper that expects structured inputs from another component. The main risk is misunderstanding or poor decomposition output, not local system access or data exposure.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The skill documentation is written entirely in Chinese and does not offer any mechanism to respect the user's preferred language or provide bilingual fallback. In multi-agent or user-facing environments, this can cause misunderstandings of constraints, outputs, or error states, which may lead to incorrect actions, degraded usability, or unsafe handling when downstream components assume another language.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal