Back to skill

Security audit

效率助手 v4 基础版

Security checks across malware telemetry and agentic risk

Overview

This productivity skill is not clearly malicious, but it asks for command execution and possible network/API use while making broad local-only privacy claims.

Review this skill before installing if you handle private work tasks, business metrics, or credentials. Use it only where command execution and possible API/network access are acceptable, and avoid providing sensitive data unless you have verified how your agent will handle external APIs, callbacks, logs, and local cache files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Intent-Code Divergence

High
Confidence
95% confidence
Finding
The document claims all FREE-version data stays local and is not uploaded, but elsewhere it explicitly states some features require network access and external APIs. This mismatch can mislead users into exposing sensitive work data to remote services under a false privacy assumption, creating confidentiality and compliance risk.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger conditions are broad and based on generic natural-language intents such as data analysis or reporting, which increases the chance of unintended activation. In an agent environment with exec enabled, accidental invocation can cause unnecessary command execution, data processing, or external API use without clear user intent.

Vague Triggers

Medium
Confidence
83% confidence
Finding
Stating that users can trigger the skill through natural-language requests without defining constraints or confirmation flow makes invocation ambiguous. In a tool-capable agent, that ambiguity can translate into unintended operations or data handling based on conversational text that was not meant as an execution request.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill says the agent will automatically call tools or APIs and the manifest includes exec, but the user-facing description does not clearly warn that shell commands may be run. This reduces informed consent and can lead users to provide inputs that trigger command execution or environment inspection they did not expect.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.