Back to skill

Security audit

CarBuying-CN 国内购车顾问

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Chinese car-buying guide with a local calculator and no evidence of hidden access, persistence, data theft, or destructive behavior.

Install if you want Mainland China car-buying planning help. Treat loan, tax, insurance, registration, and negotiation guidance as estimates and verify current local rules and contract terms before making financial commitments.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger terms are broad enough to activate on many generic car-related queries, which can cause unintended skill invocation and override more appropriate skills or general assistant behavior. In a transactional domain like car buying, misrouting can lead to irrelevant financial or legal guidance being surfaced when the user did not explicitly ask for this workflow.

VirusTotal

67/67 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.