Back to skill

Security audit

KAIFASKILLFZ01

Security checks across malware telemetry and agentic risk

Overview

This is a transparent development-workflow skill that plans, implements after approval, reviews, and saves workflow notes, with no hidden executable code or malicious behavior found.

Install this if you want a structured coding workflow that may create plan and review files under plans/ and use subagents. For security-sensitive, payment, authentication, production, or large changes, explicitly request strict mode; if you only want advice or an in-chat plan, tell the agent not to save plan/review files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The natural-language trigger rules are broad enough that ordinary discussion about software development can unintentionally activate the skill, causing the agent to enter a more powerful multi-step workflow than the user intended. That increases the risk of unauthorized file creation, plan archival, or sub-agent spawning based on ambiguous conversational input, especially in mixed-use chat contexts.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The auto-entry criteria in the trigger section are ambiguous and keyword-based, making the skill susceptible to accidental or adversarial invocation through routine discussion containing terms like '开发', '实现', or '重构'. In a system that can spawn sub-agents and write artifacts to disk, unintended activation materially expands the action surface and can lead to workflow execution without clear user consent.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The phrase “小功能” is ambiguous and commonly appears in ordinary development requests, so it may trigger the quick variant without deliberate user intent. Because the quick variant downgrades review depth and skips security review, this ambiguity can cause under-reviewed changes to be produced.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The phrase “小功能” is ambiguous and commonly appears in ordinary development requests, so it may trigger the quick variant without deliberate user intent. Because the quick variant downgrades review depth and skips security review, this ambiguity can cause under-reviewed changes to be produced.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The phrase “不用太正式” is a weak conversational cue that can silently select the quick workflow. In this skill context, that is dangerous because quick review explicitly skips security checks, allowing an attacker or even an unintentional user phrase to downgrade the review pipeline.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.