Back to skill

Security audit

小沐宝咖啡

Security checks across malware telemetry and agentic risk

Overview

This is a static coffee-stall helper skill with child-safety and privacy caveats, but no executable code, hidden behavior, credential access, or exfiltration evidence.

Install only if a parent or guardian is comfortable maintaining the child persona, schedule/location details, payment language, and social-media templates. Before using it publicly, remove ad hoc contact collection, use a parent-managed announcement channel, and add clear rules for photos or videos involving the child.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The auxiliary trigger terms include very broad, everyday coffee-related words such as '拉花' and '阿拉比卡', which can appear in many unrelated conversations about coffee. This can cause the skill to activate outside its intended scope, leading to irrelevant responses, context hijacking, or unintended disclosure of brand-specific templates in non-target chats.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The condition '且有上下文时触发' is ambiguous because it does not define what counts as sufficient context or when the skill must not activate. Ambiguous activation logic increases the chance of inconsistent routing and accidental invocation, especially when paired with broad trigger words.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The template encourages asking customers to leave contact information for future stall updates, but provides no limits on what data to collect, no parental handling guidance, and no privacy notice. In this context, the skill is for a 7-year-old child operating a coffee stall, which makes casual collection of personal data more sensitive because it can expose customers' contact details and create child-safety and data-handling risks.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.