danjiegun

Security checks across malware telemetry and agentic risk

Overview

This is a markdown-only branding and personal IP positioning guide, with no hidden execution or privileged behavior found.

Install this if you want a Chinese-language assistant for personal or team branding positioning. Avoid sharing confidential client data, financial details, or private business strategy unless you are comfortable discussing them in the chat, and review any suggested content changes yourself before acting.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger examples are broad conversational phrases like '帮我做一下三节棍定位' and '我是做XX的,帮我梳理一下定位', which can overlap with ordinary user requests and cause the skill to activate unintentionally. In an agent environment, over-broad activation increases the chance of misrouting user intent, unexpected disclosure of user/business details into the skill workflow, and poor control over when this methodology is invoked.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal