Back to skill

Security audit

重大疾病距离模拟器

Security checks across malware telemetry and agentic risk

Overview

This skill has a coherent health-education purpose, but it asks for sensitive health details and may use them in external searches without clear consent, privacy, or data-sharing limits.

Review before installing. Use it only if you are comfortable discussing sensitive health and family-history information with the agent, avoid names or precise identifiers, and ask for confirmation that external searches will use minimized or generalized details. Treat its report as health education, not medical advice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger phrases are broad enough that ordinary health-related conversation could activate the skill unintentionally. In this skill's context, accidental activation is more dangerous because it leads directly into collection of sensitive health and lifestyle data and may start personalized risk analysis without clear user intent.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill does not define clear activation boundaries or exclusion conditions, so the agent may invoke it in ambiguous contexts. Because the skill performs quasi-medical profiling and uses external retrieval based on personal attributes, ambiguous activation increases the risk of collecting or processing sensitive data without informed consent.

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill is designed to collect highly sensitive personal data, including health status, family history, BMI, and lifestyle details, yet it does not provide a prominent privacy notice, consent flow, retention policy, or data-sharing disclosure. In this context, that omission is serious because the collected data can reveal medical risk, genetic predisposition, and behavioral patterns, creating significant privacy and compliance exposure.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The document describes using the user's profile to drive online search/RAG queries, but it does not warn users before their sensitive attributes may be transmitted to external services. This is dangerous because search terms combining age, location, disease risk, BMI, and family history can leak health-related inferences to third-party providers or logs.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.