Back to skill

Security audit

咨询报告 Consult Report

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed consulting-report workflow that uses user-provided data or public sources to produce structured analysis, with no evidence of hidden installation, persistence, credential use, or destructive behavior.

Before installing, consider whether you want a Chinese-first consulting-report workflow. Only provide data files you intend the agent to analyze, and for complex S-level tasks be aware it may use parallel subagents for bounded hypothesis validation if the host environment supports that.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill description includes broad trigger phrases like 写咨询报告、行业分析、市场研究、竞争分析、战略分析、增长策略、写报告, which are common user intents and lack tight invocation boundaries. This can cause the skill to activate in overly broad situations, steering unrelated tasks into its workflow and potentially overriding more appropriate, safer, or narrower skills.

Natural-Language Policy Violations

Medium
Confidence
76% confidence
Finding
The skill description is written to operate in Chinese and does not offer a user language choice, which can force language switching or produce outputs in a language the user did not request. While not a direct code-execution risk, it can degrade user control, cause misunderstanding of analytical conclusions, and increase the chance of misuse in multilingual environments.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The skill hard-codes Chinese as the output language without indicating that this should depend on user preference or locale. This can override the user's requested language, causing instruction-priority conflicts and potentially misleading or unusable output in multilingual environments, though it does not directly create a code-execution or data-exfiltration risk.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.