Back to skill

Security audit

展会与研讨会 ROI 量化评估师

Security checks across malware telemetry and agentic risk

Overview

This appears to be a disclosed event/seminar ROI analysis skill, with no evidence of hidden access, persistence, credential use, destructive behavior, or data exfiltration.

Installers should treat this as a benign analytical skill, but provide clear event name, timeframe, costs, revenue, and assumptions when using it. Avoid sharing confidential financial details unless you are comfortable having the agent process them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The README instructs users to invoke the skill with very broad natural-language prompts about any event or seminar, without clear boundaries, required inputs, or trigger constraints. Overly broad invocation guidance can cause the agent to activate in unintended contexts, increasing the chance of misuse, scope creep, or unreliable analysis based on incomplete or ambiguous user input.

VirusTotal

56/56 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.