Back to skill

Security audit

Ai Kujiale Design Free

Security checks across malware telemetry and agentic risk

Overview

The skill has a plausible interior-design purpose, but it asks the agent to use an account token and run unbundled local scripts under broad activation conditions.

Review this skill before installing. Only use it in a workspace where you know what ./scripts/*.js contains, keep the Kujiale access token scoped and private, and require explicit confirmation before any account-backed or quota-consuming action.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Context-Inappropriate Capability

Medium
Confidence
96% confidence
Finding
The skill instructs the agent to run `ping` for troubleshooting, which is unrelated to the core interior-design workflow and expands behavior into arbitrary network diagnostics. Even though `ping` is not inherently destructive, allowing a skill to trigger network probes creates unnecessary outbound network activity and can be abused for environment discovery or policy bypass in agent runtimes that expose `exec`.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger condition '用户提到要做室内设计/装修设计' is broad enough to activate on generic discussion about design rather than an explicit request to use this skill. Overbroad activation increases the chance the agent will enter a workflow that reads tokens, runs local scripts, or invokes paid/external actions without sufficiently clear user intent.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The repeated trigger description remains ambiguous and duplicates the same weak activation boundary later in the document, reinforcing that the workflow may start on loosely related conversation. In this skill, ambiguous triggering is more dangerous because the skill has `exec` access and can perform external operations tied to a user token and potentially quota-consuming actions.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.