Back to skill

Security audit

China Mirror Resolver

Security checks across malware telemetry and agentic risk

Overview

This skill is openly built to fix slow downloads, but it can persistently change package and system update sources, so users should review and approve changes carefully.

Install only if you want an agent to help change package mirror settings. Before applying any fix, require a preview of the exact tool, mirror URL, config file, backup path, commands, and rollback steps; manually approve sudo/admin changes and prefer well-known HTTPS institutional mirrors over search-result mirrors.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The README explicitly promotes automatic discovery, validation, and configuration of package mirrors, but it does not clearly warn users that local package manager settings may be modified. In a security-sensitive context, changing registries or mirror endpoints can redirect software supply chains and persist beyond the current session, increasing the risk of unintended trust in third-party infrastructure.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger set is broad enough to activate on ordinary networking or package-management discussions, which can cause the agent to enter a workflow that changes package sources unexpectedly. In this skill, activation can lead to persistent configuration changes and use of third-party mirrors, so accidental invocation meaningfully increases risk.

Vague Triggers

Medium
Confidence
80% confidence
Finding
The Cursor adaptation example uses generic trigger words like timeout, mirror, and 下载慢 that are common in normal development conversations. Because this skill can recommend or apply persistent mirror reconfiguration, vague auto-triggering raises the chance of unrequested system-wide source changes.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill instructs permanent modification of package-manager and system configuration without a strong upfront warning that this changes trust boundaries and may route future installs through third-party mirrors. That is dangerous because it can persist beyond the immediate troubleshooting session and affect all later dependency retrieval.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.