Back to skill

Security audit

提示词架构师专业版

Security checks across malware telemetry and agentic risk

Overview

This is a prompt-engineering guidance skill with some broad tool and troubleshooting notes, but I found no hidden persistence, exfiltration, destructive behavior, or purpose-incompatible actions.

Install only if you want a Chinese-language prompt-engineering assistant and are comfortable granting its declared read/exec/write-style agent tools for prompt testing and validation. Keep network checks, external API use, credential setup, and any generated test scripts under explicit user control.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Context-Inappropriate Capability

Medium
Confidence
86% confidence
Finding
The error-handling guidance instructs users to run network connectivity tests ('ping') and inspect firewall/proxy settings even though the skill is presented as a prompt-engineering platform. That broadens operator behavior into external network diagnostics and can normalize unnecessary tool or network usage, increasing the chance of unintended outbound activity in environments where the skill should remain documentation-focused.

Intent-Code Divergence

Medium
Confidence
82% confidence
Finding
The file claims to be 'MD+EXEC' and 'pure Markdown instructions' with exec only for validation scripts, but other sections direct operational behavior involving external tools, APIs, and network troubleshooting. This mismatch can mislead reviewers and users about the real execution and connectivity surface, causing the skill to be trusted or enabled under weaker controls than appropriate.

Vague Triggers

Medium
Confidence
79% confidence
Finding
The top-level description is broad and generic, covering prompt architecture, efficiency improvement, workflows, and configuration guidance without tight activation constraints. Overbroad scope increases the likelihood that the skill activates for many unrelated requests, which can override more appropriate instructions and expand the circumstances under which exec/read/write-enabled behavior is brought into a session.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The coverage-keyword section enumerates many broad phrases and generic business terms that can match ordinary user requests. In a skill with read/exec/write/glob/grep tools, such broad activation logic raises the risk of accidental invocation and scope creep, exposing powerful tooling in contexts not specifically intended for prompt-architecture work.

Natural-Language Policy Violations

Medium
Confidence
70% confidence
Finding
The skill is written and positioned as a Chinese-localized professional edition without clear user opt-in for language preference. This is mainly a scope/usability issue, but forced localization can also reduce clarity of safety-critical instructions for users expecting another language, increasing misconfiguration risk rather than creating a direct exploit path.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.