Back to skill

Security audit

Product Direction Review

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only Chinese product review framework with no code, credentials, network access, persistence, or hidden system authority.

Safe to install from a security perspective. Expect an opinionated Chinese-language product and business-model review workflow; in ambiguous conversations, ask the agent to confirm before applying it and request your preferred language if needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrases are broad, common requests such as asking to 'look at' or 'evaluate' a product idea, which can cause the skill to activate unintentionally in normal conversation. This creates over-broad routing behavior: users may be pushed into this opinionated review workflow when they did not explicitly ask for it, leading to unwanted instruction injection into the conversation and reduced user control.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The skill is written to operate in Chinese throughout and does not offer a user-language choice, which can override the user's preferred language and reduce transparency about what the agent is doing. While this is not a direct security exploit, it can impair informed consent, cause misunderstanding of outputs, and make mis-trigger consequences harder for non-Chinese users to detect or correct.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.