Back to skill

Security audit

广州开公司 - 新手老板注册全流程顾问

Security checks across malware telemetry and agentic risk

Overview

This is a text-only Guangzhou company-registration advisor with disclosed branded Chinese output and no hidden execution, credential access, or persistence beyond normal skill installation.

Install this only if you want a Chinese, Guangzhou-focused company-registration advisor from the named service brand. It may ask for business, shareholder, legal representative, phone, and address details when drafting formal plans, so share that information only in an authorized advisor workflow and still verify official fees, timelines, and legal or tax advice independently.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (10)

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The file description for `SKILL.md` explicitly says it contains '语言与署名规范', and the README itself is entirely framed for a Chinese-language workflow. There is no indication anywhere in this file that users may choose another language or locale, which can constitute a language/locale policy violation under the natural-language policy rules.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The file prescribes customer-facing language as Chinese-style colloquial wording and gives no option for users to choose another language or locale. Under the policy, forcing a specific language without opt-in is a natural-language policy concern unless the locale restriction is clearly documented and justified.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
Line L57 states that this internal content must not enter the customer-facing dialogue body and that the customer version should only provide ranges, expressed entirely as a fixed Chinese-facing communication instruction. There is no indication that users may choose another language or that the locale restriction is required for a region-specific compliance reason, which can violate language/locale policy requirements.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
Line L06 requires all customer-visible content endings/footers to include a fixed Chinese signature. This is a natural-language locale policy concern because it mandates a specific language presentation without indicating user opt-in or that the skill is explicitly limited to a Chinese-language or region-specific workflow.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
Line L04 requires responses to be '通俗可执行' in a customer-facing mode, and the rest of the scenarios are written entirely in Chinese with output expectations that imply Chinese-only delivery. This is a natural-language locale constraint without any indication that users may choose another language or that the restriction is explicitly justified as region-specific policy.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The document explicitly sets '语言 = 平实' and the entire deliverable is specified in Chinese, which constitutes a language/locale constraint in natural-language instructions. There is no indication that the user can choose another language or that the constraint is optional, so this appears to violate the language-choice policy.

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
The file's instructions, prompts, and operational guidance are all presented only in Chinese, which imposes a specific language on users and operators. Under the stated policy, forcing a language without explicit user opt-in is a natural-language policy violation unless the locale restriction is documented and justified, which is not present here.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The file’s natural-language instructions, headings, and templates are all Chinese, and there is no indication that users may opt into another language or that the skill is restricted to a Chinese-speaking or China-specific audience. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The entire skill instruction set is written in Chinese and targets internal advisors/sales workflows, but it does not state that Chinese is optional or that the skill is limited to a Chinese-language operating context. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The instruction requiring every reply to end with a fixed Chinese signature forces a specific language/branding element regardless of user preference or context. While not directly enabling code execution or data exfiltration, it reduces user-consent and can interfere with system-level response policies, localization expectations, or neutral assistant behavior.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.