Back to skill

Security audit

小包子Hello技能

Security checks across malware telemetry and agentic risk

Overview

This is a simple greeting skill that prints localized Hello World messages and does not show data access, networking, persistence, or privileged behavior.

Safe to install for testing or basic greeting use. Consider narrowing the trigger phrases to something like hello-world or xiaobaozi-hello to reduce accidental activation in normal conversation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The manifest registers very generic trigger phrases such as "hello", "world", and "greeting", which are common in normal user conversation and likely to cause unintended activation or routing conflicts with other skills. While this does not indicate malicious behavior, it can degrade safety and reliability by making the skill easier to invoke accidentally and harder for users to control predictably.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal