Back to skill

Security audit

崖州区企业服务

Security checks across malware telemetry and agentic risk

Overview

This is a coherent enterprise-service reporting skill, but users should handle generated reports and company data carefully.

Install only if you intend to use web search and dependent skills for Yazhou District enterprise-service work. Confirm the company identity before lookup, avoid entering unnecessary confidential or personal data, review .docx reports before sharing, and verify policy, financial, and safety conclusions against official sources.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger list includes broad phrases such as "企业服务", "优惠政策", and "发展建议", which are common in ordinary government or business conversations. This can cause unintended invocation of the skill in unrelated contexts, potentially exposing enterprise data workflows or causing the assistant to produce authoritative policy/regulatory outputs when the user did not explicitly request this skill.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger list includes broad phrases such as '企业服务', '优惠政策', and '发展建议', which can cause the skill to activate in unrelated conversations. In a government/enterprise-service context, accidental invocation can expose enterprise-query, policy-analysis, and report-generation workflows when the user did not intend to use this skill, increasing the risk of inappropriate data retrieval or document creation.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill instructs the agent to always generate `.docx` reports, including multi-enterprise reports, but does not clearly notify the user that files will be created or that potentially sensitive enterprise information may be compiled into a portable document. In this context, silent file generation increases the chance of over-collection, unintended persistence, and accidental sharing of business-sensitive or compliance-related information.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.