Back to skill

Security audit

meta-skill-system

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly a coherent Chinese meta-methodology skill, but its broad activation scope and under-scoped shell/Python fallback make it something users should review before installing.

Install only if you want a broad Chinese-language meta-skill that may guide agents through skill generation, workflow restructuring, web research, file operations, and possible shell/Python use. Prefer using it with explicit task boundaries and require confirmation before it runs commands, writes files, edits generated skills, or uses external search results.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Context-Inappropriate Capability

Medium
Confidence
96% confidence
Finding
The skill explicitly endorses fallback to general-purpose bash/Python tooling, which materially expands its execution surface beyond methodology and content generation. In an agent environment, broad shell or Python access can be repurposed to read local files, invoke networked tools, transform data unsafely, or chain into further capability abuse if user input or downstream content is adversarial.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger list is extremely broad and includes generic phrases such as '任务执行', '技能生成', and '创新框架' without clear activation boundaries, exclusions, or scoping rules. In an agent environment, this can cause unintended invocation of the skill for loosely related prompts, increasing the chance that this powerful meta-skill overrides more specific skills or is applied in contexts the user did not intend.

Natural-Language Policy Violations

Medium
Confidence
77% confidence
Finding
The skill metadata and content are written entirely in Chinese and do not offer any language-selection rule or fallback, which can force interactions into a language the user did not request. While not directly a code-execution issue, this can degrade user control, cause misunderstanding of constraints or outputs, and make security-relevant instructions easier to miss in multilingual environments.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The template instructs generated skills to include trigger words but does not constrain them to be narrow, contextual, or paired with exclusion conditions. In a meta-skill system that generates other skills, overly broad triggers can cause unintended invocation, prompt hijacking surface expansion, or accidental routing of unrelated user requests into high-privilege workflows.

Natural-Language Policy Violations

Medium
Confidence
86% confidence
Finding
The file content is entirely in Chinese and presents the methodology as the default operating language without offering any language-selection mechanism or justification. In a general-purpose meta-skill, this can cause user intent mismatch, misinterpretation of safety-critical instructions, and exclusion of users or downstream agents that expect another language, which increases the chance of operational errors.

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
The requirements file is written entirely in Chinese and frames outputs/structures in a way that effectively assumes Chinese-language operation, without any visible user-language negotiation or opt-in at the top-level requirements. In a general-purpose meta-skill that can be applied across many domains, this can cause user intent mismatch, reduce reviewability for non-Chinese users, and increase the chance that users approve actions or outputs they cannot fully understand.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger list contains broad generic phrases such as task execution and workflow refactoring, increasing the chance that the skill activates for ordinary requests outside its intended scope. Over-broad activation can cause unintended instruction takeover, tool exposure, or prompt-context substitution, especially because this skill includes expansive operational guidance and tooling rules.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.