抓取某个微博用户在某个时间发的微博内容。只需要说:抓一下XXX的微博。

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward workflow for browsing public Weibo pages and extracting posts, with a minor risk that broad trigger phrases could activate it unintentionally.

Install this only if you want your agent to browse m.weibo.cn and collect public Weibo posts. Give specific target accounts and date ranges, and consider privacy, site terms, and rate limits before repeated or bulk scraping.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are broad and overlap with common user language such as “weibo”, “看微博”, and “微博内容”, which can cause the skill to activate when the user did not intend to invoke browser automation. Unintended activation is risky because this skill performs live navigation and scraping actions against external sites, increasing the chance of unnecessary data access, unexpected browsing, or interference with more appropriate skills.

VirusTotal

57/57 vendors flagged this skill as clean.

View on VirusTotal