Back to skill

Security audit

JIANYAOFANGAN01

Security checks across malware telemetry and agentic risk

Overview

The skill appears to support proposal-document drafting, but it stores potentially sensitive proposal data locally and sends generated documents to Feishu without enough upfront disclosure or user control.

Review before installing if proposals may contain confidential business, government, security, budget, or infrastructure information. Use it only with non-sensitive or redacted content unless you are comfortable with local JSON persistence and Feishu cloud upload; ask for local-only output and delete saved proposal state when finished.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Context-Inappropriate Capability

Low
Confidence
70% confidence
Finding
The skill instructs the agent to scan the local proposals/ directory and enumerate all saved proposal state files when resuming work. This can expose unrelated historical project names, progress, and timestamps to a user who only requested continuation, creating an unnecessary local data-disclosure surface across sessions.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill defines persistent local storage of proposal content in JSON files without any explicit warning, consent, retention policy, or handling guidance. Because proposals may contain sensitive government, enterprise, network, or budgeting information, silent persistence increases the risk of unintended local disclosure and residual data exposure.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill instructs the agent to upload generated documents to Feishu cloud storage without an explicit privacy or data-transfer warning. Since the workflow is intended for government/state-owned enterprise IT planning and may include security planning, budgets, and operational details, undisclosed transfer to external cloud storage materially increases confidentiality risk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.