Back to skill

Security audit

quick-proposal

Security checks across malware telemetry and agentic risk

Overview

This is a simple text-only proposal-writing skill with no evidence of hidden commands, credential use, persistence, or data exfiltration.

Reasonable to install if you want a lightweight Chinese proposal-writing template. Provide concrete project requirements, budget assumptions, and timeline constraints before using its estimates, and verify any generated costs or schedules before sending them to clients.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The invocation examples are very broad natural-language requests and do not define clear activation boundaries, exclusions, or required context. In an agent environment, this can cause the skill to trigger on loosely related user input and generate proposals in contexts where it was not intended, increasing the chance of inappropriate execution, prompt collisions, or misuse with sensitive project data.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal