Back to skill

Security audit

Task Ops

Security checks across malware telemetry and agentic risk

Overview

This is a coherent task-workflow skill, but it can activate very broadly and direct agents to create or save new skills and use tools without clear user-confirmation boundaries.

Review before installing. This skill is best used when you explicitly want a Chinese task-operations framework or skill-generation workflow. Avoid allowing it to auto-activate on generic task requests, and require confirmation before it reads or writes files, runs code, performs web searches, or saves generated skills.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger list contains very broad, everyday terms such as '执行', '内容', '创新', '任务系统', and 'Pipeline', which can match many unrelated user requests and cause the skill to activate unexpectedly. This increases the chance of prompt hijacking of normal conversations into this skill's workflow, potentially changing agent behavior, causing inappropriate file reads, or producing outputs under the wrong operating mode.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The module activation rules use subjective conditions like '领域边界模糊', '存在历史遗留问题', and '满足重构判断标准' without clear guardrails, making it easy for the model to route similar requests into different modules inconsistently. Ambiguous routing can lead the agent to load unnecessary reference files, follow unintended workflows, or overreach into strategic evaluation and restructuring when the user's request was narrower.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger list is extremely broad and includes generic productivity terms such as '执行', '工作流', '任务分解', and 'Pipeline', which can cause the skill to activate in many unrelated conversations. Overbroad activation increases the chance that the skill's strong operating framework and tool-usage guidance will steer user interactions unexpectedly, creating confusion and unsafe context switching.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill explicitly allows tool use including web search, file read/write, and code execution as implementation choices, but it does not require a user-facing warning or confirmation step for impactful operations. In practice, this can lead an agent to perform external actions or handle sensitive local data under the generic 'pipeline execution' model without clearly surfacing operational risk to the user.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill metadata and content define very broad triggers around generic concepts like task systems, pipelines, workflow refactoring, execution, and innovation. This can cause the skill to activate for ordinary user requests outside its intended scope, leading to prompt hijacking of unrelated conversations and unintended behavior steering by the skill.

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
The framework is written to produce Chinese-language structured outputs and naming conventions without any indication that this should be conditional on user preference. If auto-applied, it can override the user’s requested language or system defaults, causing instruction conflict, degraded usability, and possible misrouting of downstream automation that expects another language.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The activation condition is very broad: any request to create a knowledge base or domain payload skill can trigger this module, which increases the chance of unintended invocation during ordinary help-style conversations. In a skill that can generate structured outputs and proceed toward file creation, overbroad triggering can cause unauthorized or surprising actions to be taken based on ambiguous user intent.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The module explicitly instructs writing generated skills into a target directory but does not mention any user-facing warning, confirmation, sandbox restriction, or path validation. In an agentic context, undocumented file-writing behavior can lead to unexpected filesystem modification, overwriting existing content, or writing to attacker-influenced locations if downstream parameters are not tightly controlled.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The workflow is designed to trigger on a wide set of common task-management and pipeline-related phrases, many of which are ordinary user intents rather than a clear request to invoke this skill. That creates a prompt-routing risk where the skill may activate unexpectedly, causing unintended behavior, context hijacking, or inappropriate transformation of a user's request into this generator workflow.

Natural-Language Policy Violations

Medium
Confidence
83% confidence
Finding
The document is written as a Chinese-only operational workflow and does not provide a language selection or preservation rule, which can cause the system to override the user's preferred language during execution. In an agent setting this can degrade usability, create misunderstandings in generated artifacts, and increase the chance of incorrect outputs when user requirements are multilingual or non-Chinese.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger section allows activation from very generic requests like asking for breakthrough directions or innovation help, which can cause the skill to take over interactions without clear user intent or scope confirmation. In an agent setting, overly broad invocation increases the chance of misrouting ordinary requests into this skill, producing unexpected behavior and widening the surface for prompt confusion or unsafe autonomy.

Natural-Language Policy Violations

Medium
Confidence
97% confidence
Finding
The file is written entirely in Chinese and does not offer a language choice, fallback, or an explicit locale restriction. This can cause users or downstream agents who do not read Chinese to misunderstand instructions, skip important constraints such as compliance requirements, or misuse the skill due to incomplete comprehension.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.