Back to skill

Security audit

北京早安心情助手(天气+穿衣+饮食)

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only Beijing morning weather helper with a minor chance of triggering on generic greetings.

Install this if you want morning greetings to produce a Beijing weather, clothing, and food briefing. If you prefer generic greetings to stay conversational, narrow the trigger wording or use the skill only when explicitly asking about Beijing weather or weather-based advice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger conditions include very common greetings like “早安” and “早上好”, which can cause the skill to activate even when the user did not ask for weather, clothing, or food advice. This creates unintended routing risk: the assistant may override user intent, inject irrelevant location-specific content, or preempt a more appropriate skill.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill explicitly says to prioritize itself for generic morning greetings, without requiring a Beijing/weather-related signal. In a multi-skill environment, this can hijack routine salutations and cause inappropriate automatic use of web/weather tools, reducing intent accuracy and potentially exposing users to unwanted assumptions about location and preferences.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal