Li Xiang Perspective V2

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only roleplay skill for a Li Xiang-style business perspective, with no code execution or privileged access.

Install only if you want a simulated Li Xiang-style advisor. Treat responses as roleplay and decision support, not official statements from Li Xiang or Li Auto, and be aware that generic business phrases may trigger the persona.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger list includes very generic phrases such as “产品定义” and “家庭用户” that are likely to appear in ordinary business conversations, making accidental activation plausible. This can cause the agent to switch into an unintended persona and apply the skill’s framing without explicit user consent, which is a genuine prompt-routing and context-control weakness.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The expanded trigger list repeats broad, ambiguous phrases including common product and strategy terms, increasing the chance of false activation across unrelated conversations. In a roleplay skill that instructs the model to answer directly as a real founder, unintended activation is more dangerous because it can silently alter tone, authority, and decision framing.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal