Back to skill

Security audit

深度研究引擎

Security checks across malware telemetry and agentic risk

Overview

This research skill does not show malicious behavior, but its command and file-access capabilities are inconsistently described and too loosely scoped.

Review this skill before installing. It appears to be a generic research workflow rather than malware, but only use it where command execution, local file access, API keys, and callbacks are acceptable, and require explicit user approval before running shell commands or sending results to external URLs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The skill declares itself as pure Markdown/natural-language driven in one section while elsewhere advertising command execution capability. This inconsistency can mislead reviewers, policy engines, or users into granting the skill a lower-risk classification than its actual behavior warrants, increasing the chance that executable features are used without appropriate scrutiny.

Intent-Code Divergence

Medium
Confidence
98% confidence
Finding
The file presents contradictory availability classifications, first as MD+EXEC and later as MD-only. In security-sensitive agent ecosystems, classification determines trust, review depth, and permitted operations, so conflicting labels can cause unsafe routing, under-enforcement of safeguards, or operator misunderstanding about whether system commands may be run.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The description uses broad invocation language spanning SEO, keyword analysis, traffic optimization, research, and workflow use without precise trigger conditions or scope boundaries. Overbroad activation criteria can cause the agent to invoke this skill in unrelated or higher-risk contexts, especially given the presence of read/grep/glob/exec tools, which expands the blast radius of accidental or inappropriate use.

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
The skill states that it supports Chinese interaction and frames usage around Chinese-language operation without indicating user opt-in or language fallback. Forced or implicit language selection can cause user intent distortion, misinterpretation of security-relevant instructions, and review blind spots if output is generated in a language the operator did not request or cannot easily validate.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.