Back to skill

Security audit

China News

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a China-news helper, but it asks for command execution and describes broad unrelated automation that users should review before installing.

Install only if you are comfortable with a news skill that can be routed broadly and declares local command execution. Prefer a version that limits its instructions to news retrieval, removes unrelated programming/deployment language, and either removes exec or documents a narrow allowlist of commands.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The description claims the skill is for China news aggregation while also stating it should be used for code generation, programming assistance, debugging, and deployment. This kind of contradictory scope definition can cause an agent to invoke the skill in unintended contexts, increasing the chance that powerful capabilities are exposed where they are not justified.

Context-Inappropriate Capability

Medium
Confidence
96% confidence
Finding
This skill declares exec capability even though the documented purpose is primarily news retrieval and aggregation, and no concrete need for shell execution is established. Unnecessary command execution materially increases attack surface because ambiguous instructions or prompt injection from fetched content could lead an agent to run local commands.

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The capability sections describe broad workflow automation, file handling, API integration, and command execution that go well beyond a narrowly scoped China news tool. This mismatch suggests over-privileging and unclear boundaries, which makes misuse or unsafe agent routing more likely.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The invocation text is overly broad and ambiguous, mixing news retrieval with unrelated technical-assistance language. Ambiguous trigger conditions can cause an agent to select this skill for inappropriate prompts, exposing unnecessary tools and widening the chance of harmful or policy-violating behavior.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The applicability statements are contradictory and unclear, making it difficult for an agent to determine safe and appropriate use. In a skill that also exposes exec, this confusion is more dangerous because misrouting can grant command-capable handling to prompts that do not need it.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.