Back to skill

Security audit

热点分析与爆款挖掘

Security checks across malware telemetry and agentic risk

Overview

This is a public trend-analysis skill with broad activation wording, but no evidence of hidden access, persistence, credential use, destructive actions, or exfiltration.

Install this if you want the agent to use public web/trend searches for hotspot analysis and content ideation. For ordinary brainstorming, tell the agent whether you want live trend mining or general advice only.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger examples are very broad, everyday phrases such as asking for recent hot topics or topic suggestions, which can cause the skill to activate unintentionally in normal conversation. This creates overbroad routing risk: user requests may be sent to a data-mining/search skill when the user did not explicitly intend that behavior, potentially causing unnecessary external lookups, unexpected data handling, or tool overuse.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill metadata says the skill 'must' be used for broad, common requests like trending topics, topic recommendations, and content positioning advice. This can override normal intent routing and force unnecessary web/search-heavy behavior, increasing the chance of data overreach, poor tool selection, and user-request hijacking for adjacent benign advisory queries.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The activation examples cover many ambiguous everyday requests, including generic planning, tracking, and business-analysis questions. Because these examples overlap with normal assistant behavior, the skill may activate on loosely related prompts and steer conversations into unnecessary platform scraping or content-generation workflows not actually requested by the user.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.