Back to skill

Security audit

体测扫描工具免费版

Security checks across malware telemetry and agentic risk

Overview

The skill is coherent for Telegram-based body measurement, but it handles sensitive body videos and credentials with under-specified consent, retention, and secret-handling controls.

Review this skill carefully before installing. Use it only when users knowingly agree to send body videos through Telegram and the scanning service, keep bot tokens and backend credentials in secure configuration, and avoid using it for other people unless their explicit consent is obtained. Ask the publisher to clarify retention, deletion, credential handling, and activation boundaries.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Intent-Code Divergence

Medium
Confidence
88% confidence
Finding
The document states the free edition does not save historical records, yet elsewhere describes save/export/convert operations in output handling. This inconsistency can mislead users about data retention and create privacy expectations that do not match actual behavior, especially for sensitive body-measurement data.

Intent-Code Divergence

Low
Confidence
81% confidence
Finding
The skill claims it rejects local file paths and private-network URLs, but the file contains only descriptive documentation and no implementation enforcing those restrictions. If an agent or integrator relies on this claim without validation, SSRF or local file access protections may be absent in practice.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The skill uses broad health/fitness and Telegram/body-scan keywords that can cause overly eager invocation in ordinary conversations. In this context, accidental activation is more dangerous because the workflow solicits highly sensitive body videos and measurements and may trigger transmission to third-party services.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The capability coverage section declares a very broad scene/keyword scope without exclusion criteria, increasing the chance the skill activates outside appropriate contexts. Because the skill handles sensitive biometric-adjacent media and health-related outputs, overbroad activation materially raises privacy and consent risk.

Missing User Warnings

High
Confidence
96% confidence
Finding
The skill instructs users to submit body videos and receive health-related measurements through Telegram and backend services without a clear warning that this is sensitive personal data being transmitted to third parties. In this context, users may unknowingly expose intimate imagery and derived measurements without informed consent about processing, retention, or sharing.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The credential section references service credentials and Telegram bot tokens but does not warn that these are secrets that must not be exposed in prompts, logs, code snippets, or client-side output. Mishandling these values could let others access the bot or backend service and exfiltrate user data or abuse the integration.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.