Back to skill

Security audit

HiFi Review

Security checks across malware telemetry and agentic risk

Overview

This is a focused HiFi review skill with disclosed evidence-gathering and analysis scripts, and I found no hidden data access, persistence, credential use, or destructive behavior.

Install this if you want measurement-driven HiFi evaluations and are comfortable with the skill doing live source retrieval and running local read-only analysis scripts on supplied files. Be aware that it may activate on HiFi evaluation requests and its long-form mode defaults to Chinese-primary output.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill enables implicit invocation while advertising a broad natural-language trigger in the default prompt, which can cause the agent to activate this skill unexpectedly during ordinary conversation about HiFi devices. This is primarily a security and safety boundary issue: unintended activation may expose user prompts or steer the conversation into this skill without explicit user intent, even though the skill itself is not high-risk.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The template hard-codes Chinese output length and format requirements without any visible user-consent or locale-selection mechanism. This can override user language expectations and steer the agent into producing mismatched or inaccessible output, which is a prompt-quality and policy-compliance risk even if it is not directly code-executing.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The rule permits activation when the model itself 'judge[s] a deep writeup is wanted', creating an implicit trigger not strictly tied to explicit user intent. That can cause the skill to override user preferences, unexpectedly switch output mode, and weaken predictability and policy compliance in downstream systems that rely on deterministic routing.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The skill hard-requires Chinese-primary output regardless of the user's language preference, which can conflict with user expectations, accessibility needs, or platform-level language controls. In a bilingual review skill this is less severe than in a safety-critical domain, but it still creates an avoidable loss of user control and can produce non-compliant or unusable responses for some users.

Hidden Instructions

High
Category
Prompt Injection
Content
<!-- Long-form 评测长文 skeleton. Copy the matching block, fill each section from the
     evidence set ONLY. Strip these HTML comments before delivering. Target ~4000字
     (CJK), band 3500–4500. Run scripts/check_longform.py to verify. -->
Confidence
95% confidence
Finding
<!-- Long-form 评测长文 skeleton. Copy the matching block, fill each section from the evidence set ONLY. Strip these HTML comments before delivering. Target ~4000字 (CJK), band 3500–4500. Run scr

Hidden Instructions

High
Category
Prompt Injection
Content
# 《<设备名>》客观评测长文

## 一、开篇与定位
<!-- ~400字, 先验/规格: 类型、定位价位、单元构型、品牌家族/前作血缘. 标注 [先验] -->

## 二、客观测量
<!-- ~700字, 实测: 测量台(711/GRAS)与对齐 target(Harman IE/OE/IEF/DF)、对齐方式、
Confidence
93% confidence
Finding
<!-- ~400字, 先验/规格: 类型、定位价位、单元构型、品牌家族/前作血缘. 标注 [先验] --> ## 二、客观测量 <!-- ~700字, 实测: 测量台(711/GRAS)与对齐 target(Harman IE/OE/IEF/DF)、对齐方式、 8 频段量感向量逐条、整体偏离. 给出 fr_analyze 的 dev_db/quanta. 标注 [实测] -->

Hidden Instructions

High
Category
Prompt Injection
Content
8 频段量感向量逐条、整体偏离. 给出 fr_analyze 的 dev_db/quanta. 标注 [实测] -->

## 三、三频解析
<!-- ~900字, 实测: 低频(sub/mid_bass) / 中频(lower/center/upper) / 高频(treble/air)
     各自相对 target 的量感与听感映射;窄峰/凹陷单列为 flagged feature. -->

## 四、风格与调音
Confidence
93% confidence
Finding
<!-- ~900字, 实测: 低频(sub/mid_bass) / 中频(lower/center/upper) / 高频(treble/air) 各自相对 target 的量感与听感映射;窄峰/凹陷单列为 flagged feature. -->

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.