Back to skill

Security audit

Hologres Bsi Profile Analysis

Security checks across malware telemetry and agentic risk

Overview

This is a coherent Hologres BSI profile-analysis guide, with disclosed database write steps that users should review before running.

Before installing, verify the `hologres-cli` source, connect only to the intended Hologres instance and schema, review every `--write` SQL command, and protect the generated UID dictionary, bitmap, and BSI tables according to your data-governance rules.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger list includes broad terms such as "画像分析", "用户画像", and "标签计算", which are generic concepts rather than narrowly scoped invocation phrases. In a manifest description, these terms can overlap with ordinary discussion of analytics work and may activate the skill outside the intended Hologres BSI-specific context.

Vague Triggers

Medium
Confidence
90% confidence
Finding
This manifest file includes trigger phrases such as "画像分析", "用户画像", and "标签计算", which are fairly broad terms for profile analysis and tag computation. Without tighter scope constraints or negative examples, the skill may match ordinary data-analysis requests beyond the intended Hologres BSI context.

Natural-Language Policy Violations

Low
Confidence
84% confidence
Finding
The natural-language description is written entirely in Chinese and presents the skill purpose and triggers only in that language, aside from a few technical tokens. This can be a language/locale policy issue when the skill does not offer an explicit user choice or state that it is intentionally limited to Chinese-speaking users.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.