Back to skill

Security audit

AI Agent OS: SkyDome Taiyi / 天穹-太一

Security checks across malware telemetry and agentic risk

Overview

The skill is a disclosed persona and workflow workbench with local helper scripts; it has privacy and command-use cautions but no evidence of deception, exfiltration, or unsafe automatic behavior.

Install this only if you want a strong Taiyi persona/workflow overlay that can run local helper scripts and create local state files. Treat outputs from diagnostics, benchmarking, log analysis, memory, review, and dream reports as potentially sensitive; review them before sharing, and do not point the helpers at repositories, logs, or state files containing secrets unless you are comfortable with that data appearing in local files or chat output.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Context-Inappropriate Capability

Medium
Confidence
74% confidence
Finding
The script provides a direct arbitrary-command execution capability that is broader than a simple benchmark utility and can be dangerous when bundled inside an AI-agent skill. In an agent context, users or upstream prompts may cause the agent to invoke this helper on attacker-chosen commands, turning the skill into a command-execution primitive with access to local files, credentials, and network-reachable resources.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The activation examples include very broad phrases like '启动太一' / 'Activate Taiyi' / 'Run Celestial One' that could be uttered in quoted text, discussion, testing, or documentation and still trigger a persona shift. Unintended activation can override the assistant's normal behavior and cause it to adopt alternate operating instructions at the wrong time, increasing prompt-injection and mis-execution risk.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The activation section says to enter Taiyi mode if the user says any listed phrase, but it does not define exclusions for mentions in analysis, quotations, code blocks, translations, or adversarial prompt content. Because the skill is persona-heavy and changes behavior globally, underspecified activation makes accidental or malicious triggering more likely and can let untrusted content steer the assistant into a different instruction regime.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The skill hard-codes a prescribed opening phrase in Chinese without user opt-in, which can override user language preferences and reduce assistant compliance with downstream instructions or accessibility expectations. In a persona/core cognition file, this is more likely intentional branding than abuse, but it still creates unnecessary response steering that can conflict with user intent and platform policies.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The script aggregates recent task, memory, and review contents into a timestamped markdown report and persists that report to disk, which can duplicate sensitive material into a new location with broader retention and discoverability. Even though the output is framed as a 'safe dream report,' there is no redaction, consent prompt, sensitivity filtering, or warning before copying potentially confidential data from state files and reviews into the output.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.