Back to skill

Security audit

Personal Office Aasistant

Security checks across malware telemetry and agentic risk

Overview

This is a text-only Chinese personal office assistant skill with no code execution or hidden access, though its marketplace description is too terse and its short prompts may route broad office tasks unexpectedly.

Reasonable to install if you want a Chinese-language office drafting and organization helper. Be aware that brief Chinese office-style prompts may be interpreted broadly, review outputs before using them for legal, financial, contract, performance, or public-facing work, and avoid pasting passwords, keys, or unnecessary sensitive business data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The manifest description materially understates the skill’s actual capabilities, which include broad drafting, meeting support, planning, and document-processing functions. This can mislead reviewers, users, or policy systems about the scope of the skill, reducing transparency and making governance and risk assessment less reliable.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The skill defines very generic trigger interpretations such as short phrases like '帮我写一下' or '整理一下,' which are common in ordinary conversation. If the platform uses these patterns for routing or activation, the skill could be invoked unintentionally, causing context leakage, user confusion, or inappropriate takeover of requests that were not meant for this skill.

Natural-Language Policy Violations

Medium
Confidence
80% confidence
Finding
The skill content is written entirely in Chinese and establishes a Chinese-language operating context without indicating language negotiation or user choice. This can cause mismatched responses for users expecting another language and may lead to usability failures or misunderstanding, though it is not a high-severity security issue by itself.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.