Back to skill

Security audit

Muniu Liumia

Security checks across malware telemetry and agentic risk

Overview

This is a coherent planning and audit skill for turning requirements into implementation guidance, with expected project-reading behavior and no hidden install, persistence, or destructive actions.

Install this if you want a Chinese-first structured PRD-to-implementation workflow. Be aware that when used in an existing project it may read project files for architecture context or audit; invoke it only in repositories you are comfortable having analyzed, and specify your preferred output language if Chinese is not desired.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill defines broad natural-language triggers such as '解析这份需求', '做架构设计', and '检查完成情况', which can easily match ordinary project conversation and cause the skill to activate without clear user intent. In a skill that can steer multi-phase analysis and recommend next steps, accidental invocation can lead to unintended processing of sensitive project documents or workflow hijacking away from the user's immediate request.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The skill content is entirely authored in Chinese and prescribes fixed Chinese output/report formats without any indication that the user can choose another language. This can cause the agent to ignore the user’s preferred locale, increasing the risk of misunderstood audit results, missed remediation steps, or unsafe operator actions in a security-sensitive workflow.

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.