China Research

Security checks across malware telemetry and agentic risk

Overview

This skill is a public market-research helper that searches Chinese social platforms and summarizes findings, with no evidence of hidden local access or destructive behavior.

Use this for public or non-sensitive market research. Before installing, confirm which mcporter/search backend your environment uses, and do not enter confidential product plans, customer data, or private business ideas unless you are comfortable sending those search terms to external search providers.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger conditions are broad enough to activate on many generic research or market-analysis requests, increasing the chance the skill runs when the user did not specifically intend external social-media research. In this skill's context, that matters because activation can cause user topics to be sent to third-party search providers and may shape the assistant into using a narrower, potentially privacy-impacting workflow by default.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill instructs the agent to send user-provided topics to external search services and search third-party sites, but it does not warn users that their prompts may leave the system boundary. This creates a privacy and data-handling risk, especially if users include confidential business ideas, sensitive market plans, or personal data in the research topic.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal