Back to skill

Security audit

Market Analysis Cn Hardened

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed paid market-analysis skill with no executable code, credentials, persistence, or hidden data access.

Before installing, treat this as a paid consulting-style skill: confirm the exact service tier and price before any charge, avoid sharing confidential business data unless you have a separate agreement, and require named credible sources for market-size or growth claims.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The manifest includes broad trigger phrases such as '市场分析', '竞品分析', 'market analysis', and '趋势', which can match ordinary user requests and cause the skill to activate too eagerly. In a paid analysis skill, overbroad invocation increases the risk of unsolicited routing into a monetized workflow, user confusion, and accidental use outside clear user intent.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal