Back to skill

Security audit

Auto Expert Team

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly markdown guidance, but it broadly activates and steers agents into high-impact domains like social automation, invoice handling, legal work, and investment advice without clear safeguards.

Install only if you intentionally want a broad expert-team routing template. Treat it as Review-worthy: keep activation explicit, avoid letting it post or automate social interactions, do not use it for personalized financial or legal decisions, and only provide invoice or business files when you understand where they will be read, stored, and shared.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The file materially contradicts the skill's declared purpose by bundling a massive catalog of simulated experts and teams across many domains. This kind of hidden capability expansion increases the chance of deceptive routing, unexpected behavior, and misuse because users and reviewers cannot rely on the manifest to understand what the skill actually enables.

Context-Inappropriate Capability

Medium
Confidence
89% confidence
Finding
The catalog exposes broad capabilities spanning legal, finance, security, HR, marketing, cloud operations, and more, far beyond the stated purpose of the skill. Overbroad latent capability is dangerous because it expands attack surface, encourages out-of-scope use in regulated domains, and makes policy enforcement harder when a supposedly narrow skill can be repurposed widely.

Intent-Code Divergence

Medium
Confidence
87% confidence
Finding
The content repeatedly promotes multi-role expert-team collaboration even though the skill description says such simulation is unnecessary. This inconsistency is dangerous because it can conceal the true operating model, weaken trust in safety review, and cause downstream systems or users to invoke higher-risk workflows under misleading assumptions.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The trigger phrases are broad and include common terms like '专家团' and '团队协作完成任务,' which can cause the skill to activate on ordinary requests unrelated to this specific workflow. Over-broad activation increases the chance that the skill overrides user intent, injects irrelevant process scaffolding, or causes unintended behavior across many benign conversations.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The activation rule 'any task beyond a single person's ability' is highly subjective and effectively self-expanding, allowing the skill to claim relevance for a large set of complex requests. In practice, this can lead to unsolicited takeover of task flow and make skill invocation unpredictable, which is dangerous in agent environments where deterministic routing and user intent fidelity matter.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill advertises automated social-media interaction and AI comment operations across many platforms without warnings about platform rules, consent, spam/inauthentic behavior, or reputational harm. In this context, the capability is more dangerous because it is framed as scalable expert automation, which could facilitate policy violations, account sanctions, or coordinated manipulation.

Missing User Warnings

Low
Confidence
80% confidence
Finding
The file promotes one-click fully automated short-video generation and delivery without any warning about factual accuracy, copyright, deepfake risk, or need for human review before publication. While lower impact than financial or legal automation, it still creates risk of misinformation, brand damage, and accidental publication of unsafe or infringing content.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The invoice workflow processes uploaded files or local folders for recognition, verification, credit checks, and archiving without warning about handling sensitive financial and business data. This is more dangerous in context because the feature implies bulk access to documents and local files, increasing privacy, confidentiality, and data-governance risk if users are not clearly warned and protected.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill advertises investment analysis that outputs BUY/SELL/HOLD recommendations and complete operation plans without any financial-risk disclaimer or limitation notice. In a finance context this is especially dangerous because users may over-rely on the system for consequential decisions, potentially causing financial loss and creating compliance or unauthorized-advice issues.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
Advertising 24/7 investment consulting by digital personas without warning about limitations, data quality, model error, or regulatory boundaries can mislead users into treating the system as a trustworthy advisory service. The context makes this more dangerous because continuous availability and expert framing can amplify undue reliance in a regulated, high-stakes domain.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.