Huang Zheng Perspective

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only business-analysis persona skill with no code execution, data access, or hidden install behavior.

Install this only if you want a Huang Zheng-inspired business analysis lens. Treat first-person answers as simulation based on public information, not as real statements from Huang Zheng, and independently verify facts or decisions with business consequences.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger conditions are intentionally broad and include generic business phrases like '这个商业模式靠谱吗' and '逆向思考一下', which can cause the skill to activate in ordinary conversations where the user did not ask for persona simulation. That creates control-flow hijacking risk: the assistant may switch into a specific persona and apply constrained behavior unexpectedly, reducing response relevance and potentially overriding stronger default safety or neutrality behaviors.

Natural-Language Policy Violations

Medium
Confidence
81% confidence
Finding
The skill's language adaptation section directs outputs toward Chinese-only style without preserving user language preference. While not a direct security exploit, it can degrade user control and cause instruction-priority conflicts by making the agent ignore the language the user actually requested, which is a form of unwanted behavioral override.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal