Back to skill

Security audit

夸克扫描-免费版

Security checks across malware telemetry and agentic risk

Overview

The skill appears intended for Quark image/document scan enhancement, but its trigger and permissions are broader than its stated single-image purpose and could cause sensitive files to be handled or uploaded unexpectedly.

Install only if you intend to use it for explicit single-image scanning or enhancement tasks. Do not let it process arbitrary documents or sensitive files unless you are comfortable uploading them to Quark's service, and prefer narrowing the trigger language before routine use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger condition is phrased so broadly ('需要文件处理、文档转换、格式互转、内容提取时使用') that it can match many unrelated user requests involving files or documents. In an agent environment with exec/write tools enabled, this increases the chance the skill is invoked outside its intended image-enhancement scope, leading to unnecessary handling of local files, external uploads, or execution of commands on sensitive content.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.