Back to skill

Security audit

中国商标查询 Skill

Security checks across malware telemetry and agentic risk

Overview

The skill is a disclosed Chinese trademark search connector, with a billing-language inconsistency users should verify before relying on trial credits.

Before installing, verify the current trial-credit terms in the platform UI because the English and Chinese pricing text disagree. Treat the platform token like a password, use HTTPS, and expect trademark queries and usage history to be processed by the hosted service in mainland China.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The English and Chinese versions define materially different trial-point terms: English says 10 trial points expiring in 30 days, while Chinese says 100 trial points expiring in 90 days. In a billing document, contradictory language can mislead users about cost, entitlement, and expiry, creating dispute risk and enabling selective enforcement based on user language.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
Inconsistent bilingual policy content can cause users to accept different effective terms depending on which language they read, without explicit disclosure or consent. In this pricing context, that can affect trial credits and expiry expectations, leading to unfair treatment, complaints, chargebacks, or regulatory scrutiny for deceptive or unclear billing practices.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access, suspicious.exposed_secret_literal

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/cli.test.mjs:54

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/cli.mjs:323

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
API_CONTRACT_EN.md:68

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
API_CONTRACT.md:68