产品分析大法-双轴洞察引擎

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed research-report skill that may use web research and save report files, with no hidden code, credential use, or destructive behavior found.

Install this if you want long, source-backed research reports. Before use, note that default PDF delivery may create files on your Desktop and in an analysis archive, and optional Feishu output may publish content into a third-party document system. Verify high-impact business, investment, policy, or technical claims independently.

Publisher note

ChronoPrism is an instruction-only research framework skill. It contains no executable scripts, no package install steps, no bundled dependencies, no background jobs, and no required environment variables or credentials. Expected behavior: It may guide the agent to use available read-only research tools, such as web search or page fetching, when current public information or citations are needed. It instructs the agent to treat fetched web pages, papers, posts, comments, and retrieved documents as untrusted source material, not as instructions to follow. It may generate research briefs, decision memos, competitor analyses, technical evaluations, or PM opportunity scans in chat. It should create or edit files only when the user explicitly asks for a saved artifact. It does not request account access, tokens, local secrets, shell execution, package installation, persistent scheduling, autonomous loops, or account-changing actions. Primary risk: External sources can be incomplete, outdated, biased, or adversarial. Users should verify high-impact claims and treat outputs as decision support rather than definitive proof. Suggested audit context: Expected risk level: low. Expected behavior type: instruction-only research and synthesis. Any finding related to read-only web access or optional user-requested Markdown output is purpose-aligned.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill defaults to generating a PDF at a local Desktop path (`~/Desktop/<报告名>.pdf`) without prominently warning that it will create files on the user's machine. Silent or implicit local file creation can surprise users, overwrite existing files if names collide, or expose sensitive report contents in a commonly synced or visible location such as the Desktop.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal