Back to skill

Security audit

Qq Zone Photo Tool Free

Security checks across malware telemetry and agentic risk

Overview

This QQ Zone photo skill is mostly purpose-aligned, but its routing text mixes in unrelated project-management uses while requesting exec/write access and handling QQ login sessions.

Review this before installing. Use it only for your own QQ Zone photos, avoid giving it broad automation authority, keep QQ cookies private, and do not rely on its project-management wording because that appears unrelated to the actual skill. The package should narrow its manifest and capability text and include or clearly identify the scripts it expects agents to run.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The manifest description injects unrelated project-management and team-collaboration use cases into a QQ Zone photo-management skill, creating a misleading identity for the tool. This can cause incorrect routing or user trust in contexts the skill does not actually support, increasing the chance of unintended invocation and unsafe execution of its read/write/exec capabilities.

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The capability-coverage statement claims support for scenarios such as project management, task planning, and team collaboration even though the documented behavior is limited to QQ photo access. This broadens the apparent scope of the skill and can make an agent invoke it for unrelated prompts, creating confusion and potentially exposing local execution paths in the wrong workflow.

Vague Triggers

High
Confidence
96% confidence
Finding
The manifest uses overly broad, mismatched trigger language unrelated to photo management, which is a skill-routing risk rather than a mere documentation issue. In an agent ecosystem, this can hijack prompts intended for other domains and cause this skill to be selected unexpectedly, after which its exec/write permissions could be exercised in an inappropriate context.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The scope statement enumerates vague keywords like 'Use', 'when', and unrelated business-planning terms that could match a wide range of user requests. Because the skill exposes exec capability, accidental triggering is more dangerous than for a read-only skill: an agent may invoke local commands for a task wholly outside the intended domain.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.