Back to skill

Security audit

网盘同步专家

Security checks across malware telemetry and agentic risk

Overview

The skill is a plausible Baidu Netdisk manager, but it needs review because some high-impact actions are under-scoped or inconsistently confirmed.

Review this skill before installing. It may be useful for Baidu Netdisk automation, but only run it where you are comfortable granting command execution, remote file mutation, public sharing capability, and possible local agent-memory overwrite. Be especially cautious with install/update scripts and permanent share links.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Intent-Code Divergence

High
Confidence
97% confidence
Finding
The skill repeatedly claims that all operations are restricted to /apps/bdpan/, but the memory restore workflow explicitly writes to local workspace memory files and creates local backup directories outside that path. This mismatch can mislead users and calling agents about the true trust boundary, enabling unintended local file modification under the guise of a remote-netdisk-only tool.

Tool Parameter Abuse

High
Category
Tool Misuse
Content
| 风险等级 | 操作 | 策略 |
| --- | --- | --- |
| **高(必须确认)** | `rm` 删除、上传/下载目标已存在同名文件 | 列出影响范围,等待用户确认 |
| **中(路径模糊时确认)** | upload、download、mv、rename、cp | 路径明确直接执行,不明确则确认 |
| **低(直接执行)** | ls、search、whoami、mkdir、share | 无需确认 |
Confidence
86% confidence
Finding
rm` 删除、上传/

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.