Back to skill

Security audit

C盘清理员

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Windows C-drive cleanup skill with clear safety limits and user confirmation requirements, though users should verify any cleanup script before running it.

Install only if you want a Windows C-drive cleanup assistant. Run DryRun first, review each directory prompt, and do not approve deletion unless the path is expected. If you use the referenced PowerShell script from another source, inspect it first because the script itself was not included in this artifact.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrase "安全清理" is generic and can match user requests unrelated to C-drive cleanup, increasing the chance this skill is invoked outside its intended scope. Because the skill can launch a PowerShell cleanup script, over-broad routing may cause users to trigger disk-cleanup actions they did not specifically request.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.